PT-2026-28387 · Fleet · Fleet
Secfox-Ai
·
Published
2026-03-27
·
Updated
2026-04-07
·
CVE-2026-29180
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fleet versions prior to 4.81.1
Description
Fleet is open source device management software. A broken access control vulnerability exists in the host transfer API. A team maintainer can transfer hosts from any team into their own team, bypassing team isolation boundaries. Once transferred, the attacker gains full control over the stolen hosts, including the ability to execute scripts with root privileges. The host transfer endpoints verify write permission to the destination team but do not check permission over the source team. A bulk transfer variant allows stealing all matching hosts fleet-wide in a single request. Exploitation requires authentication as a team maintainer or team admin.
Recommendations
Versions prior to 4.81.1 should be upgraded. Organizations concerned about exploitation should audit host transfer activity in Fleet logs for any unexpected team reassignments.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fleet