Privilege Escalation in Fleet Device Management Software by FleetDM
CVE-2026-27806

7.8HIGH

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-27806?

Fleet is open-source device management software that contains a vulnerability which allows local users to exploit the password input mechanism for FileVault disk encryption key rotation. Prior to version 4.81.1, the Orbit agent's handling of a local user’s password through a GUI dialog directly modifies a Tcl/expect script. The vulnerability arises because the injected password can inadvertently contain special characters, leading to the execution of arbitrary Tcl commands with root privileges. This poses a significant risk, as it allows for unauthorized privilege escalation by unprivileged users on the affected systems.

Affected Version(s)

fleet < 4.81.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.