Cyber & AI intelligence
Wasteland.
Briefs indexed2957
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-103264 2026-10-01

Fleet Device API Authentication Bypass (CVE-2026-103264)

"An authentication bypass in Fleet versions before 4.87.0 lets an unauthenticated attacker pose as an iOS/iPadOS host by using non-secret identifiers such as hostnames or hardware serial numbers."

An authentication bypass in Fleet versions before 4.87.0 lets an unauthenticated attacker pose as an iOS/iPadOS host by using non-secret identifiers such as hostnames or hardware serial numbers.

What Is It

CVE-2026-103264 is an authentication bypass (CWE-287) in the device API of Fleet, the device management platform from fleetdm. Affected versions accept a device UUID as an authentication token, which is expected. They also accept hostnames and hardware serial numbers as tokens. These identifiers are not secret. An attacker who knows or guesses one can authenticate as an iOS/iPadOS host.

VulnCheck disclosed the vulnerability. NVD published it on 2026-10-01, and its NVD status is currently "Received."

Why It Matters

Once authenticated as an iOS/iPadOS host, an attacker can:

VulnCheck scores the flaw as Critical:

Hostnames and serial numbers are often visible or easy to work out, so in practice these identifiers do little to stop an attacker. The ability to start software installs or MDM migration means the flaw can affect the integrity of managed devices, not just expose data.

Exploitation status: As of 2026-10-01, CVE-2026-103264 is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, so CISA has not confirmed active exploitation.

What's Vulnerable

Patch Status

The issue is fixed in Fleet 4.87.0. Organizations running an earlier version should upgrade to 4.87.0 or later. As of 2026-10-01, the CVE is not in the KEV catalog, so no CISA required action or remediation due date applies. See the vendor's GitHub security advisory for upgrade details.

Sources