CVE-2026-54245: Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database
(updated )
A SQL injection vulnerability in Fleet’s Okta conditional access integration could allow an attacker who controls a single enrolled host to read or modify arbitrary data in the Fleet database, including stored session tokens. Disclosed session tokens may be replayed to act as a global administrator, which on a managed fleet leads to remote code execution on enrolled hosts.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54245 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →