CVE-2026-24004: Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint
A vulnerability in Fleet’s Android MDM Pub/Sub handling could allow unauthenticated requests to trigger device unenrollment events. This may result in unauthorized removal of individual Android devices from Fleet management.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-24004 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →