Vulnerability in Fleet Affects In-House iOS Application Packages
CVE-2026-101047

6.9MEDIUM

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101047?

Fleet versions earlier than 4.87.0 lack protection for endpoints that serve in-house iOS application packages and manifests, which can be accessed using predictable URL tokens. The requirement for these URLs to be reachable without a Fleet session complicates session-based authentication, allowing unauthorized users with network access to potentially retrieve IPA binaries along with their metadata by guessing URL identifiers. The vulnerability primarily leads to read-only disclosure of sensitive application data, while ensuring there is no possibility for privilege escalation or writing to the server. It is important to note that users on the free tier of Fleet are not affected by this issue.

Affected Version(s)

fleet 0 < 4.87.0

fleet 4.87.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.