Description
Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration.
Published: 2026-10-01
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized Device Control
Action: Immediate Patch
AI Analysis

Impact

The flaw is an authentication bypass in Fleet versions prior to 4.87.0 that allows unauthenticated attackers to provide hostnames or hardware serial numbers as valid authentication tokens for the device API in addition to device UUIDs. Because these identifiers are not considered confidential, an attacker who knows or can guess them can authenticate as an iOS or iPadOS device and obtain device‑level data or invoke device‑scoped actions such as software installation or MDM migration. The weakness is identified as Authentication Bypass (CWE‑287).

Affected Systems

All installations of fleetdm fleet running a version earlier than 4.87.0 are affected. The vulnerability applies universally to the product and has no vendor‑specific variants beyond the fleetdm supply chain. Exact affected deployment environments include any fleet deployment that exposes the device API to external networks or untrusted actors.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical impact, while the EPSS score is currently not available, leaving the frequency of exploitation uncertain. The vulnerability is not listed in the CISA KEV catalog, so no known exploits have been reported in public threat intelligence. The likely attack vector is via network‑based API requests that target the device authentication endpoint; the description does not provide explicit details of network exposure, so the vector is inferred from the API nature of the flaw and the fact that it accepts credentials over HTTP/HTTPS. Att device hostnames or serial numbers, which are often accessible externally, making discovery feasible for attackers with minimal effort. Overall, the combination of high CVSS and easily guessable non‑secret identifiers renders the risk high and the exploitation likely if the API is exposed to untrusted environments.

Generated by OpenCVE AI on October 1, 2026 at 14:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Fleet to version 4.87.0 or later to remove the authentication bypass
  • If upgrading is delayed, restrict the device API to require authenticated users only or disable hostname/serial identifier authentication for device access
  • Implement network segmentation and firewall rules to limit exposure of the Fleet API to trusted infrastructure

Generated by OpenCVE AI on October 1, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration.
Title Fleet before 4.87.0 Authentication Bypass via Device Identifiers
First Time appeared Fleetdm
Fleetdm fleet
Weaknesses CWE-287
CPEs cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:*
Vendors & Products Fleetdm
Fleetdm fleet
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T13:32:04.417Z

Reserved: 2026-09-30T10:58:33.573Z

Link: CVE-2026-103264

cve-icon Vulnrichment

Updated: 2026-10-01T13:30:43.190Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T11:17:21.410

Modified: 2026-10-01T15:09:04.013

Link: CVE-2026-103264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:15:09Z

Weaknesses