
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29180 is a broken access control vulnerability in Fleet's host transfer API that allows an authenticated team maintainer to transfer hosts from any team into their own team, bypassing team isolation boundaries. It affects Fleet (open source device management software) versions prior to 4.81.1, developed by FleetDM. The vulnerability was disclosed on March 27, 2026, with a patch released in version 4.81.1. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 4.9 (Medium) (GitHub Advisory, Github Advisory).
The root cause is a missing authorization check (CWE-862) in Fleet's host transfer API endpoints. The endpoints verify that the caller has write permission to the destination team but fail to validate whether the caller has any permission over the source team from which hosts are being transferred. An attacker authenticated as a team maintainer or team admin can craft API requests over the network — with no user interaction required — to move hosts from any team into their own, including a bulk transfer variant that can steal all matching hosts fleet-wide in a single request (GitHub Advisory, Github Advisory).
Once hosts are transferred, the attacker's team MDM configuration is automatically applied to the stolen devices, and the attacker can execute arbitrary scripts on them with root privileges. In multi-tenant Fleet deployments where teams represent business units, departments, or customers, this completely breaks team isolation guarantees, enabling cross-tenant compromise. The bulk transfer variant amplifies the impact by allowing an attacker to seize all matching hosts across the entire Fleet deployment in a single request, with full confidentiality, integrity, and availability impact on the affected hosts (GitHub Advisory).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability requires authentication as a team maintainer or team admin, which limits the attacker pool to insiders or compromised accounts. The EPSS score is approximately 0.038% (0.022% per GitHub Advisory), placing it in a low exploitation probability tier. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
GET /api/v1/fleet/hosts) to identify target hosts belonging to other teams.POST /api/v1/fleet/hosts/transfer or the bulk variant), specifying the IDs of hosts from a team the attacker does not have permission over, and setting the destination team to the attacker's own team.Upgrade Fleet to version 4.81.1 or later, which patches the missing source team authorization check in the host transfer API. There is no functional workaround short of upgrading. As interim measures, organizations should restrict team maintainer and team admin roles to only fully trusted personnel, monitor Fleet audit logs for unexpected host transfer activity between teams, and review team membership assignments for anomalies (GitHub Advisory, Github Advisory).
The vulnerability was responsibly disclosed by researcher @secfox-ai (credited as prateek-0490) and published by Fleet maintainer lukeheath on March 27, 2026. Fleet's security team acknowledged the issue and released a patch promptly. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database aggregation (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."