CVE-2026-103264
Received Received - Intake

Authentication Bypass in Fleet Device API via Hostname or Serial

Vulnerability report for CVE-2026-103264, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fleetdm fleet to 4.87.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Fleet versions before 4.87.0 have an authentication bypass in the device API. Attackers can use hostnames or hardware serials instead of device UUIDs to authenticate as iOS/iPadOS devices. This allows unauthorized access to device data and actions like software installation.

Detection Guidance

To detect this vulnerability, check Fleet server logs for unauthorized API access attempts using hostnames or hardware serials as authentication tokens instead of device UUIDs. Inspect network traffic for iOS/iPadOS device API requests with non-UUID identifiers. Verify Fleet server version; versions below 4.87.0 are vulnerable.

Impact Analysis

Unauthenticated attackers can read sensitive device data, install or uninstall software, and migrate devices to another MDM. This includes accessing device details, policies, and certificates. The impact is high due to the ability to perform privileged actions without authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) by exposing confidential device and user information. Compliance may be compromised if unauthorized access occurs.

Mitigation Strategies

Immediately upgrade Fleet to version 4.87.0 or later to patch the authentication bypass. Until then, restrict network exposure of the Fleet server and treat all iOS/iPadOS host identifiers as sensitive credentials. Monitor for suspicious API activity and unauthorized device actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103264. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart