
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27806 is a local privilege escalation vulnerability in FleetDM's Orbit agent, caused by Tcl command injection during the FileVault disk encryption key rotation flow. The vulnerability affects FleetDM Fleet versions prior to 4.81.1 and was disclosed on April 8, 2026. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Fleet Security Advisory).
The root cause is improper neutralization of special elements in an OS command (CWE-78) and improper control of code generation (CWE-94). During FileVault key rotation, the Orbit agent collects a local user's password via a GUI dialog and interpolates it directly into a Tcl/expect script using exec.Command("expect", "-c", script). The password is inserted into a Tcl brace-quoted send {%s} construct; a password containing the } character terminates the brace literal and allows injection of arbitrary Tcl commands. Because Orbit runs as root, any local user with low privileges can craft a password containing } followed by malicious Tcl commands to achieve root-level code execution with no user interaction required (GitHub Advisory, Fleet Security Advisory).
Successful exploitation grants a local unprivileged user full root privileges on the managed endpoint, resulting in complete compromise of confidentiality, integrity, and availability. An attacker can execute arbitrary commands as root, read or modify any file on the system, install persistent backdoors, or use the compromised host as a pivot point for lateral movement within the network. All macOS endpoints managed by a vulnerable Fleet/Orbit deployment and configured for FileVault key rotation are at risk (GitHub Advisory).
No public exploit code or in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.007% (1st percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified. The vulnerability was discovered and responsibly reported by bugbunny.ai (Fleet Security Advisory).
} to terminate the Tcl brace literal, followed by arbitrary Tcl commands — for example: } ; exec /bin/bash -c {chmod u+s /bin/bash} ;send {exec.Command("expect", "-c", script).orbit or expect process running as root (e.g., /bin/bash, sh, python, curl, nc)./bin/bash with chmod u+s); new cron jobs, launchd plists, or scripts created by root in unusual locations; unauthorized SSH keys added to /root/.ssh/authorized_keys./var/log/system.log entries showing expect process execution with anomalous arguments during FileVault key rotation events; Orbit agent logs recording unusual password input patterns or Tcl evaluation errors.FleetDM has released a patched version, Fleet 4.81.1, which resolves this vulnerability. Organizations should upgrade all Orbit agents to version 4.81.1 or later as the primary remediation (GitHub Advisory, Fleet Security Advisory). As a temporary workaround where immediate upgrade is not possible, consider disabling the FileVault disk encryption key rotation feature in Fleet until the patch can be applied. Restrict local user access on managed endpoints to reduce the attack surface.
The vulnerability was discovered and reported by bugbunny.ai and published by FleetDM maintainer lukeheath on April 8, 2026 (Fleet Security Advisory). No significant broader media coverage or notable public researcher commentary beyond the advisory itself has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."