cvedb.io
CVE-2026-23999
MEDIUM · CVSS 5.5
EPSS exploitation probability: 0%
Published 2026-02-26T03:16:04.010 · Last modified 2026-06-17T10:22:27.287

Summary

Fleet is open source device management software. In versions prior to 4.80.1, Fleet generated device lock and wipe PINs using a predictable algorithm based solely on the current Unix timestamp. Because no secret key or additional entropy was used, the resulting PIN could potentially be derived if the approximate time the device was locked is known. Fleet’s device lock and wipe commands generate a 6-digit PIN that is displayed to administrators for unlocking a device. In affected versions, this PIN was deterministically derived from the current timestamp. An attacker with physical possession of a locked device and knowledge of the approximate time the lock command was issued could theoretically predict the correct PIN within a limited search window. However, successful exploitation is const

Affected products

fleetdm — fleet

Does this affect you?

Add your gear to cvedb and we'll alert you only when fleetdm ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.