Broken Access Control in Fleet Device Management Software by FleetDM
CVE-2026-29180

4.9MEDIUM

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-29180?

Fleet, an open-source device management software, has reported a broken access control vulnerability within its host transfer API prior to version 4.81.1. This flaw enables a team maintainer to exploit access controls and transfer hosts from any team into their own. By bypassing team isolation mechanisms, unauthorized users can gain complete control over transferred hosts, including the capacity to execute scripts with root privileges. Fleet version 4.81.1 addresses and resolves this critical access control issue.

Affected Version(s)

fleet < 4.81.1

References

CVSS V4

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.