CVE-2026-29180 describes a broken access control vulnerability in Fleet's host transfer API, affecting versions prior to 4.81.1. This flaw allows a team maintainer to bypass team isolation boundaries and transfer hosts from any team into their own. Rated 8.8 HIGH, the vulnerability has low attack complexity and requires only low privileges, enabling an attacker to gain full control over stolen hosts and execute scripts with root privileges. While the potential impact is severe, there is currently no evidence of active exploitation, nor are public exploit codes or significant community discussion available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.81.1CPE matchmatch criteria | cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.