Authentication Bypass in Fleet Device API by FleetDM
CVE-2026-103264

9.3CRITICAL

Key Information:

Vendor

Fleetdm

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103264?

Prior to version 4.87.0, FleetDM's Fleet is susceptible to an authentication bypass vulnerability within its device API. This flaw allows unauthenticated attackers to exploit non-secret identifiers, such as hostnames and hardware serials, which are accepted as authentication tokens alongside device UUIDs. By leveraging knowledge or guessing these identifiers, an attacker can impersonate iOS/iPadOS devices to access sensitive device data and initiate actions that should be restricted, such as software installations or device management migrations.

Affected Version(s)

fleet 0 < 4.87.0

fleet 4.87.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.