Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration. | |
| Title | Fleet before 4.87.0 Authentication Bypass via Device Identifiers | |
| First Time appeared |
Fleetdm
Fleetdm fleet |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fleetdm
Fleetdm fleet |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T10:42:06.306Z
Reserved: 2026-09-30T10:58:33.573Z
Link: CVE-2026-103264
No data.
Status : Received
Published: 2026-10-01T11:17:21.410
Modified: 2026-10-01T11:17:21.410
Link: CVE-2026-103264
No data.
OpenCVE Enrichment
No data.