—
GO-2026-6264
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet
Quick fix
GO-2026-6264 — github.com/fleetdm/fleet/v4: upgrade to the fixed version with the command below.
go get github.com/fleetdm/fleet/v4@v4.86.2Details
Fleet: SQL injection in Okta conditional access endpoint allows host-controlled compromise of the Fleet database in github.com/fleetdm/fleet
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/fleetdm/fleet/v4
Introduced in:
0Fixed in: 4.86.2Fix
go get github.com/fleetdm/fleet/v4@v4.86.2