CVE-2026-101045: Arbitrary Command Execution in Fleet's macOS App Install and Uninstall Scripts
A vulnerability in Fleet's macOS app install and uninstall scripts, generated from Homebrew cask metadata, allows an attacker to achieve arbitrary command execution as root on managed macOS hosts. The vulnerability, with a CVSS score of 8, was patched in Fleet v4.92.0 and does not require customer action for remediation.