Skip to content
Threat Feed
critical threat exploited

Authentication Bypass in Fleet Device API

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that allows unauthenticated attackers to spoof iOS or iPadOS devices using predictable identifiers.

CVE search metadata

CVE search record: CVE-2026-103264. Severity: critical. CVSS: 9.1. KEV: no. Product: Fleet (< 4.87.0). Brief: Authentication Bypass in Fleet Device API. Brief link: https://feed.craftedsignal.io/briefs/2026-10-fleet-auth-bypass/

Fleet versions prior to 4.87.0 are affected by an authentication bypass vulnerability located in the device API. The application improperly accepts hostnames or hardware serial numbers as valid authentication tokens in addition to the required device UUIDs. Because hostnames and serial numbers are often discoverable or guessable, an unauthenticated attacker can effectively spoof a legitimate iOS or iPadOS host. Successful exploitation allows the attacker to authenticate as a registered device, facilitating unauthorized access to sensitive device data. Furthermore, the attacker can influence device-scoped operations, such as triggering unauthorized software installations or migrating device management (MDM) configurations, posing a significant risk to fleet integrity and security posture.

Impact

Successful exploitation of this vulnerability permits unauthorized access to sensitive device information and enables the execution of administrative actions across the fleet. Attackers may conduct unauthorized software deployments or move devices to malicious MDM environments, potentially leading to total loss of control over affected endpoints.

Recommendation

  • Upgrade all instances of Fleet to version 4.87.0 or later to remediate the authentication bypass vulnerability in the device API (CVE-2026-103264).
  • Review access logs for the device API to identify unexpected authentication attempts originating from anomalous sources or those using non-UUID tokens if logging granularity permits.

Immediate actions

Upgrade Fleet to version 4.87.0 or later

IT Operations 24h

Mitigations

Patch Fleet software to 4.87.0

immediate IT Operations

CVE-2026-103264