Broken Access Control in Fleet Device Management Software by FleetDM
CVE-2026-29180
4.9MEDIUM
What is CVE-2026-29180?
Fleet, an open-source device management software, has reported a broken access control vulnerability within its host transfer API prior to version 4.81.1. This flaw enables a team maintainer to exploit access controls and transfer hosts from any team into their own. By bypassing team isolation mechanisms, unauthorized users can gain complete control over transferred hosts, including the capacity to execute scripts with root privileges. Fleet version 4.81.1 addresses and resolves this critical access control issue.
Affected Version(s)
fleet < 4.81.1
