PT-2026-31406 · Fleet · Fleet

·

CVE-2026-27806

·

Published

2026-04-08

·

Updated

2026-07-30

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fleet versions prior to 4.81.1
Description The Orbit agent’s FileVault disk encryption key rotation flow collects a local user’s password via a GUI dialog and interpolates it directly into a Tcl/expect script executed via exec.Command("expect", "-c", script). Because the password is inserted into Tcl brace-quoted send {%s}, a password containing } terminates the literal and injects arbitrary Tcl commands. Since Orbit runs as root, this allows a local unprivileged user to escalate to root privileges.
Recommendations Update to Fleet version 4.81.1 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27806
GHSA-RPHV-H674-5HP2
GO-2026-5634
OPENSUSE-SU-2026:21483-1

Affected Products

Fleet