目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1000

100.0%

CVE-2026-46356— Fleet IP欺骗可绕过API限流漏洞

EPSS 0.07% · P20
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2026-46356 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Fleet: IP spoofing allows bypassing API rate limiting
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing client IP headers. This may allow brute-force login attempts or other abuse against Fleet instances exposed to the public internet. Fleet extracted client IP addresses from request headers (`True-Client-IP`, `X-Real-IP`, `X-Forwarded-For`) without validating that those headers originate from a trusted proxy. The extracted IP is used as the key for rate limiting and IP ban decisions. As a result, an attacker could rotate the value of these headers on each request, causing Fleet to treat each attempt as coming from a different client. This effectively bypasses per-IP rate limits on sensitive endpoints such as the login API, enabling unrestricted brute-force or credential stuffing attacks. This issue primarily affects Fleet instances that are directly exposed to the internet without a reverse proxy that overwrites forwarded-IP headers. Instances behind a properly configured proxy or WAF are less affected. Version 4.80.1 contains a patch. If an immediate upgrade is not possible, administrators should ensure Fleet is deployed behind a reverse proxy (e.g., nginx, Cloudflare, AWS ALB) that overwrites `X-Forwarded-For` with the true client IP, and apply rate limiting at the proxy or WAF layer.
来源: 美国国家漏洞数据库 NVD
CVSS Information
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
使用欺骗进行的认证绕过
来源: 美国国家漏洞数据库 NVD

受影响产品

厂商产品影响版本CPE订阅
fleetdmfleet < 4.80.1 -

二、漏洞 CVE-2026-46356 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-46356 的情报信息

登录查看更多情报信息。

同批安全公告 · fleetdm · 2026-05-14 · 共 6 条

CVE-2026-26062Fleet Server gRPC请求处理异常终止漏洞
CVE-2026-26191Fleet 软件包OS命令注入漏洞
CVE-2026-24000Fleet 通过不受信任的客户端IP头绕过速率限制漏洞
CVE-2026-24899Fleet Windows MDM Azure AD JWT认证绕过漏洞
CVE-2026-23998Fleet Windows MDM管理端点认证绕过漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-46356

暂无评论


发表评论