CVE-2026-29180
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-29180 is a broken access control vulnerability in Fleet's host transfer API that allows an authenticated team maintainer to transfer hosts from any team into their own team, bypassing team isolation boundaries. It affects Fleet (open source device management software) versions prior to 4.81.1, developed by FleetDM. The vulnerability was disclosed on March 27, 2026, with a patch released in version 4.81.1. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 4.9 (Medium) (GitHub Advisory, Github Advisory).

Technical details

The root cause is a missing authorization check (CWE-862) in Fleet's host transfer API endpoints. The endpoints verify that the caller has write permission to the destination team but fail to validate whether the caller has any permission over the source team from which hosts are being transferred. An attacker authenticated as a team maintainer or team admin can craft API requests over the network — with no user interaction required — to move hosts from any team into their own, including a bulk transfer variant that can steal all matching hosts fleet-wide in a single request (GitHub Advisory, Github Advisory).

Impact

Once hosts are transferred, the attacker's team MDM configuration is automatically applied to the stolen devices, and the attacker can execute arbitrary scripts on them with root privileges. In multi-tenant Fleet deployments where teams represent business units, departments, or customers, this completely breaks team isolation guarantees, enabling cross-tenant compromise. The bulk transfer variant amplifies the impact by allowing an attacker to seize all matching hosts across the entire Fleet deployment in a single request, with full confidentiality, integrity, and availability impact on the affected hosts (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The vulnerability requires authentication as a team maintainer or team admin, which limits the attacker pool to insiders or compromised accounts. The EPSS score is approximately 0.038% (0.022% per GitHub Advisory), placing it in a low exploitation probability tier. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Authentication: Obtain credentials for a Fleet account with at least team maintainer or team admin privileges on any team within the target Fleet deployment.
  2. Reconnaissance: Enumerate available hosts and teams in the Fleet instance using the Fleet API (e.g., GET /api/v1/fleet/hosts) to identify target hosts belonging to other teams.
  3. Craft malicious transfer request: Send an authenticated API request to the host transfer endpoint (e.g., POST /api/v1/fleet/hosts/transfer or the bulk variant), specifying the IDs of hosts from a team the attacker does not have permission over, and setting the destination team to the attacker's own team.
  4. Bypass authorization: Because the API only checks write permission on the destination team and not the source team, the transfer succeeds without authorization errors.
  5. Gain control: Once transferred, the attacker's team MDM configuration is automatically pushed to the stolen hosts. The attacker can then execute scripts with root privileges on the newly acquired devices via Fleet's script execution API (GitHub Advisory).

Indicators of compromise

  • Logs: Fleet audit logs showing host transfer events where the initiating user's team does not match the source team of the transferred hosts; unexpected bulk host reassignment entries in Fleet activity logs.
  • Fleet Activity: Hosts appearing in a team they were not previously assigned to, especially across organizational boundaries (e.g., different business units or customers).
  • MDM Configuration Changes: Sudden application of new MDM profiles or configurations to devices that were recently transferred between teams.
  • Script Execution: Fleet logs showing script execution events on hosts shortly after an unexpected team transfer, particularly scripts run with elevated (root) privileges by a team maintainer account (GitHub Advisory).

Mitigation and workarounds

Upgrade Fleet to version 4.81.1 or later, which patches the missing source team authorization check in the host transfer API. There is no functional workaround short of upgrading. As interim measures, organizations should restrict team maintainer and team admin roles to only fully trusted personnel, monitor Fleet audit logs for unexpected host transfer activity between teams, and review team membership assignments for anomalies (GitHub Advisory, Github Advisory).

Community reactions

The vulnerability was responsibly disclosed by researcher @secfox-ai (credited as prateek-0490) and published by Fleet maintainer lukeheath on March 27, 2026. Fleet's security team acknowledged the issue and released a patch promptly. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database aggregation (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management