← Volver a CVEs
CVE-2026-29180
HIGH8.8
Descripcion
Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from any team into their own team, bypassing team isolation boundaries. Once transferred, the attacker gains full control over the stolen hosts, including the ability to execute scripts with root privileges. Version 4.81.1 patches the issue.
Detalles CVE
Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado3/27/2026
Ultima modificacion3/31/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
fleetdm:fleet
Debilidades (CWE)
CWE-862
Referencias
https://github.com/fleetdm/fleet/security/advisories/GHSA-m2h6-4xpq-qw3m(security-advisories@github.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.