Authentication Bypass in Fleet Device API
Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that allows unauthenticated attackers to spoof iOS or iPadOS devices using predictable identifiers.
CVE search metadata
CVE search record: CVE-2026-103264. Severity: critical. CVSS: 9.1. KEV: no. Product: Fleet (< 4.87.0). Brief: Authentication Bypass in Fleet Device API. Brief link: https://feed.craftedsignal.io/briefs/2026-10-fleet-auth-bypass/
Fleet versions prior to 4.87.0 are affected by an authentication bypass vulnerability located in the device API. The application improperly accepts hostnames or hardware serial numbers as valid authentication tokens in addition to the required device UUIDs. Because hostnames and serial numbers are often discoverable or guessable, an unauthenticated attacker can effectively spoof a legitimate iOS or iPadOS host. Successful exploitation allows the attacker to authenticate as a registered device, facilitating unauthorized access to sensitive device data. Furthermore, the attacker can influence device-scoped operations, such as triggering unauthorized software installations or migrating device management (MDM) configurations, posing a significant risk to fleet integrity and security posture.
Impact
Successful exploitation of this vulnerability permits unauthorized access to sensitive device information and enables the execution of administrative actions across the fleet. Attackers may conduct unauthorized software deployments or move devices to malicious MDM environments, potentially leading to total loss of control over affected endpoints.
Recommendation
- Upgrade all instances of Fleet to version 4.87.0 or later to remediate the authentication bypass vulnerability in the device API (CVE-2026-103264).
- Review access logs for the device API to identify unexpected authentication attempts originating from anomalous sources or those using non-UUID tokens if logging granularity permits.
Immediate actions
Upgrade Fleet to version 4.87.0 or later
Mitigations
Patch Fleet software to 4.87.0
CVE-2026-103264