PT-2026-31406 · Fleet · Fleet

Bugbunny-Research

·

Published

2026-04-08

·

Updated

2026-04-08

·

CVE-2026-27806

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 4.81.1
Description The Orbit agent’s FileVault disk encryption key rotation flow collects a local user’s password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via exec.Command("expect", "-c", script). Because the password is inserted into Tcl brace-quoted send {%s}, a password containing } terminates the literal and injects arbitrary Tcl commands. Since Orbit runs as root, this allows a local unprivileged user to escalate to root privileges.
Recommendations Update to Fleet version 4.81.1 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-27806
GHSA-RPHV-H674-5HP2

Affected Products

Fleet