CVE-2026-26060 | fleetdm fleet up to 4.80.x Password Reset Token session expiration (GHSA-3458-r943-hmx4)
A vulnerability was found in fleetdm fleet up to 4.80.x. It has been declared as critical. This affects an unknown function of the component Password Reset Token Handler. Executing a manipulation can lead to session expiration.
This vulnerability is registered as CVE-2026-26060. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.