Vulnerability in Fleet Affects In-House iOS Application Packages
CVE-2026-101047
6.9MEDIUM
What is CVE-2026-101047?
Fleet versions earlier than 4.87.0 lack protection for endpoints that serve in-house iOS application packages and manifests, which can be accessed using predictable URL tokens. The requirement for these URLs to be reachable without a Fleet session complicates session-based authentication, allowing unauthorized users with network access to potentially retrieve IPA binaries along with their metadata by guessing URL identifiers. The vulnerability primarily leads to read-only disclosure of sensitive application data, while ensuring there is no possibility for privilege escalation or writing to the server. It is important to note that users on the free tier of Fleet are not affected by this issue.
Affected Version(s)
fleet 0 < 4.87.0
fleet 4.87.0
