CVE-2026-22808 | fleetdm fleet up to 4.53.2/4.76.1/4.77.0/4.78.1 Authentication Token FLEET::auth_token cross site scripting (GHSA-gfpw-jgvr-cw4j)
A vulnerability identified as problematic has been detected in fleetdm fleet up to 4.53.2/4.76.1/4.77.0/4.78.1. Affected is the function FLEET::auth_token of the component Authentication Token Handler. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-22808. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.