CVE-2026-29180 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to…
Medium CVSS: 4.9

CVE-2026-29180

Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host transfer API allows a team maintainer to transfer hosts from any team into their own team, bypassing team isolation boundaries. Once transferred, the attacker gains full control over the stolen hosts, including the ability to execute scripts with root privileges. Version 4.81.1 patches the issue.
Vendor
Fleetdm
Product
Fleet
CWE
CWE-862
Yayın Tarihi
2026-03-27 19:16:42
Güncelleme
2026-03-31 18:50:35
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar