Impact
The flaw is an authentication bypass in Fleet versions prior to 4.87.0 that allows unauthenticated attackers to provide hostnames or hardware serial numbers as valid authentication tokens for the device API in addition to device UUIDs. Because these identifiers are not considered confidential, an attacker who knows or can guess them can authenticate as an iOS or iPadOS device and obtain device‑level data or invoke device‑scoped actions such as software installation or MDM migration. The weakness is identified as Authentication Bypass (CWE‑287).
Affected Systems
All installations of fleetdm fleet running a version earlier than 4.87.0 are affected. The vulnerability applies universally to the product and has no vendor‑specific variants beyond the fleetdm supply chain. Exact affected deployment environments include any fleet deployment that exposes the device API to external networks or untrusted actors.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical impact, while the EPSS score is currently not available, leaving the frequency of exploitation uncertain. The vulnerability is not listed in the CISA KEV catalog, so no known exploits have been reported in public threat intelligence. The likely attack vector is via network‑based API requests that target the device authentication endpoint; the description does not provide explicit details of network exposure, so the vector is inferred from the API nature of the flaw and the fact that it accepts credentials over HTTP/HTTPS. Att device hostnames or serial numbers, which are often accessible externally, making discovery feasible for attackers with minimal effort. Overall, the combination of high CVSS and easily guessable non‑secret identifiers renders the risk high and the exploitation likely if the API is exposed to untrusted environments.
OpenCVE Enrichment