PT-2026-28387 · Fleet · Fleet

Secfox-Ai

·

Published

2026-03-27

·

Updated

2026-04-07

·

CVE-2026-29180

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 4.81.1
Description Fleet is open source device management software. A broken access control vulnerability exists in the host transfer API. A team maintainer can transfer hosts from any team into their own team, bypassing team isolation boundaries. Once transferred, the attacker gains full control over the stolen hosts, including the ability to execute scripts with root privileges. The host transfer endpoints verify write permission to the destination team but do not check permission over the source team. A bulk transfer variant allows stealing all matching hosts fleet-wide in a single request. Exploitation requires authentication as a team maintainer or team admin.
Recommendations Versions prior to 4.81.1 should be upgraded. Organizations concerned about exploitation should audit host transfer activity in Fleet logs for any unexpected team reassignments.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-29180
GHSA-M2H6-4XPQ-QW3M
GO-2026-4892
SUSE-SU-2026:1205-1

Affected Products

Fleet