CVE-2026-34388
Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Launcher endpoint allows an authenticated host to crash the entire Fleet server process by sending an unexpected log type value. The server terminates immediately, disrupting all connected hosts, MDM enrollments, and API consumers. Version 4.81.0 patches the issue.
- Affected products
- Fleet
- Fleetdm Fleet
- < 4.81.0
- Fix
- Available
- CVSS 4.0
- 8.7 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.3% (18th percentile)
- Weakness
- CWE-703
- NVD status
- Analyzed
- Published
- 2026-03-27
CVE-2026-34388 at NVD
No indexed exploits for CVE-2026-34388 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-34388 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.