CVE-2026-22808: Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability
(updated )
A cross-site scripting (XSS) vulnerability in Fleet’s Windows MDM authentication flow could allow an attacker to compromise a Fleet user account. In certain cases, this could lead to administrative access and the ability to perform privileged actions on managed devices.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-22808 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →