An authentication bypass in Fleet versions before 4.87.0 lets an unauthenticated attacker pose as an iOS/iPadOS host by using non-secret identifiers such as hostnames or hardware serial numbers.
What Is It
CVE-2026-103264 is an authentication bypass (CWE-287) in the device API of Fleet, the device management platform from fleetdm. Affected versions accept a device UUID as an authentication token, which is expected. They also accept hostnames and hardware serial numbers as tokens. These identifiers are not secret. An attacker who knows or guesses one can authenticate as an iOS/iPadOS host.
VulnCheck disclosed the vulnerability. NVD published it on 2026-10-01, and its NVD status is currently "Received."
Why It Matters
Once authenticated as an iOS/iPadOS host, an attacker can:
- Read device data
- Trigger device-scoped actions, including software installation and MDM migration
VulnCheck scores the flaw as Critical:
- CVSS 3.1: 9.1 (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). It can be attacked over the network with low complexity, no privileges and no user interaction. Confidentiality and integrity impact are both high. - CVSS 4.0: 9.3 (Critical)
Hostnames and serial numbers are often visible or easy to work out, so in practice these identifiers do little to stop an attacker. The ability to start software installs or MDM migration means the flaw can affect the integrity of managed devices, not just expose data.
Exploitation status: As of 2026-10-01, CVE-2026-103264 is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, so CISA has not confirmed active exploitation.
What's Vulnerable
- Vendor: fleetdm
- Product: Fleet (
pkg:golang/github.com/fleetdm/fleet) - Affected: all versions below 4.87.0 (semver)
- Unaffected: 4.87.0
- Impacted component: device API, specifically authentication for iOS/iPadOS hosts
Patch Status
The issue is fixed in Fleet 4.87.0. Organizations running an earlier version should upgrade to 4.87.0 or later. As of 2026-10-01, the CVE is not in the KEV catalog, so no CISA required action or remediation due date applies. See the vendor's GitHub security advisory for upgrade details.