Threats Tagged 'cve-2026-101045'
View all threats tagged with 'cve-2026-101045'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-101045'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-101045 is an OS command injection vulnerability in Fleet's app install and uninstall scripts for macOS. The vulnerability arises because Fleet-generated scripts, created from Homebrew cask metadata before 2026-08-19, did not properly escape shell metacharacters at all interpolation points. This flaw could allow an attacker who manages to insert crafted metadata into an upstream Homebrew cask to execute arbitrary commands as root on managed macOS hosts during app installation or uninstallation. The vulnerability requires the malicious metadata to pass both upstream Homebrew cask review and Fleet's automated ingestion review. The issue was fixed on 2026-08-19 by fully escaping cask metadata in all script interpolation sites, with the fix included in Fleet version 4.92.0. Because manifests are centrally generated and distributed, remediation was applied automatically without customer action. Join the discussion | CVE Database V5 | 09/27/2026, 17:02:34 UTC Added: 09/28/2026, 01:57:40 UTC |
Showing 1 to 1 of 1 result