CVE-2026-27806: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-27806 is a local privilege escalation vulnerability in FleetDM's Orbit agent, caused by Tcl command injection during the FileVault disk encryption key rotation flow. The vulnerability affects FleetDM Fleet versions prior to 4.81.1 and was disclosed on April 8, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Fleet Security Advisory).

Technical details

The root cause is improper neutralization of special elements in an OS command (CWE-78) and improper control of code generation (CWE-94). During FileVault key rotation, the Orbit agent collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script using exec.Command("expect", "-c", script). The password is inserted into a Tcl brace-quoted send {%s} construct; a password containing the } character terminates the brace literal and allows injection of arbitrary Tcl commands. Because Orbit runs as root, any local user with low privileges can craft a password containing } followed by malicious Tcl commands to achieve root-level code execution with no user interaction required (GitHub Advisory, Fleet Security Advisory).

Impact

Successful exploitation grants a local unprivileged user full root privileges on the managed endpoint, resulting in complete compromise of confidentiality, integrity, and availability. An attacker can execute arbitrary commands as root, read or modify any file on the system, install persistent backdoors, or use the compromised host as a pivot point for lateral movement within the network. All macOS endpoints managed by a vulnerable Fleet/Orbit deployment and configured for FileVault key rotation are at risk (GitHub Advisory).

Exploitability

No public exploit code or in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.007% (1st percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. The vulnerability was discovered and responsibly reported by bugbunny.ai (Fleet Security Advisory).

Exploitation steps

  1. Identify target: Confirm the target macOS endpoint is running a vulnerable version of the FleetDM Orbit agent (Fleet < 4.81.1) with FileVault disk encryption key rotation enabled.
  2. Trigger key rotation dialog: Wait for or trigger the FileVault key rotation flow, which causes Orbit to display a GUI password prompt to the local user.
  3. Craft malicious password: Enter a password containing } to terminate the Tcl brace literal, followed by arbitrary Tcl commands — for example: } ; exec /bin/bash -c {chmod u+s /bin/bash} ;send {
  4. Submit the crafted input: Submit the crafted string through the GUI dialog. Orbit interpolates it directly into the Tcl/expect script passed to exec.Command("expect", "-c", script).
  5. Achieve root execution: The injected Tcl commands execute in the context of the Orbit process running as root, granting the attacker root-level code execution on the endpoint (GitHub Advisory, Fleet Security Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the orbit or expect process running as root (e.g., /bin/bash, sh, python, curl, nc).
  • File System: Unexpected SUID/SGID bit set on binaries (e.g., /bin/bash with chmod u+s); new cron jobs, launchd plists, or scripts created by root in unusual locations; unauthorized SSH keys added to /root/.ssh/authorized_keys.
  • Logs: macOS Unified Log or /var/log/system.log entries showing expect process execution with anomalous arguments during FileVault key rotation events; Orbit agent logs recording unusual password input patterns or Tcl evaluation errors.
  • Network: Unexpected outbound connections from the managed endpoint to unknown external IPs originating from root-owned processes shortly after a FileVault key rotation event.

Mitigation and workarounds

FleetDM has released a patched version, Fleet 4.81.1, which resolves this vulnerability. Organizations should upgrade all Orbit agents to version 4.81.1 or later as the primary remediation (GitHub Advisory, Fleet Security Advisory). As a temporary workaround where immediate upgrade is not possible, consider disabling the FileVault disk encryption key rotation feature in Fleet until the patch can be applied. Restrict local user access on managed endpoints to reduce the attack surface.

Community reactions

The vulnerability was discovered and reported by bugbunny.ai and published by FleetDM maintainer lukeheath on April 8, 2026 (Fleet Security Advisory). No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management