Answer in brief
CVE-2026-54245 records a High severity (CVSS 7.6) vulnerability in Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database. The current sources do not mark it as known exploited. The current feed maps fleetdm/fleet (generic), github.com/fleetdm/fleet (go), github.com/fleetdm/fleet (go), github.com/fleetdm/fleet/v4 (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps fleetdm/fleet (generic), github.com/fleetdm/fleet (go), github.com/fleetdm/fleet (go), github.com/fleetdm/fleet/v4 (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| fleetdm/fleetgeneric | < 4.86.2 | Not reported |
| github.com/fleetdm/fleetgo | >=0 <4.86.2 | 4.86.2 |
| github.com/fleetdm/fleetgo | <4.86.2 | 4.86.2 |
| github.com/fleetdm/fleet/v4go | >=0 <4.86.2 | 4.86.2 |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 9, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 20, 2026
Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a database query without proper parameterization, allowing an attacker who controls a single enrolled host to read or modify arbitrary data in the Fleet database. The value is reported by the host's own agent and stored verbatim, then used on an unauthenticated request path that supports the conditional access integration, so any party controlling one enrolled host, the lowest-privilege position in the product, can influence the query. By disclosing arbitrary database contents an attacker can extract stored session tokens and replay them to act as a global administrator, and on a managed fleet that administrator access enables running scripts on enrolled hosts, leading to remote code execution. The issue requires Fleet Premium with the Okta conditional access integration enabled and does not affect instances where it is not configured. This issue is fixed in version 4.86.2.
Quoted source text, attributed separately from HOL analysis.