CVE-2026-103264 PUBLISHED

Fleet before 4.87.0 Authentication Bypass via Device Identifiers

Assigner: VulnCheck
Reserved: 30.09.2026 Published: 01.10.2026 Updated: 01.10.2026

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor fleetdm
Product fleet
Versions Default: unaffected
  • affected from 0 to 4.87.0 (excl.)
  • Version 4.87.0 is unaffected

References

Problem Types

  • Improper Authentication CWE