


Perceptive Security
SOC/SIEM Consultancy

Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotation flow on collects a local user's passw…
Published:
7 april 2026 om 22:00:00
Alert date:
8 april 2026 om 22:09:50
Source:
nvd.nist.gov
Security Tools, Identity & Access
Fleet open source device management software contains a privilege escalation vulnerability in the Orbit agent's FileVault disk encryption key rotation flow. The vulnerability occurs when collecting local user passwords via GUI dialog and interpolating them into Tcl/expect scripts. Passwords containing closing braces can terminate the literal and inject arbitrary Tcl commands. Since Orbit runs as root, this allows local unprivileged users to escalate to root privileges. The issue affects versions prior to 4.81.1 and has been fixed in version 4.81.1.
Technical details
Mitigation steps:
Affected products:
Fleet
Orbit Agent
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27806
https://github.com/fleetdm/fleet/security/advisories/GHSA-rphv-h674-5hp2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
