CVE-2026-48786: Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
The target search endpoint (POST /api/latest/fleet/targets) returned team enroll secrets and full team configuration, including credential-bearing agent options, to observer-class users. Other team-facing endpoints mask these fields for observers; the target search endpoint did not apply the same sanitization.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-48786 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →