Authentication Bypass in Fleet Device API by FleetDM
CVE-2026-103264
9.3CRITICAL
What is CVE-2026-103264?
Prior to version 4.87.0, FleetDM's Fleet is susceptible to an authentication bypass vulnerability within its device API. This flaw allows unauthenticated attackers to exploit non-secret identifiers, such as hostnames and hardware serials, which are accepted as authentication tokens alongside device UUIDs. By leveraging knowledge or guessing these identifiers, an attacker can impersonate iOS/iPadOS devices to access sensitive device data and initiate actions that should be restricted, such as software installations or device management migrations.
Affected Version(s)
fleet 0 < 4.87.0
fleet 4.87.0
