<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Fleet (&lt; 4.87.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/fleet--4.87.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 12:41:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/fleet--4.87.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Fleet Device API</title><link>https://feed.craftedsignal.io/briefs/2026-10-fleet-auth-bypass/</link><pubDate>Thu, 01 Oct 2026 12:41:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fleet-auth-bypass/</guid><description>Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that allows unauthenticated attackers to spoof iOS or iPadOS devices using predictable identifiers.</description><content:encoded><![CDATA[<p>Fleet versions prior to 4.87.0 are affected by an authentication bypass vulnerability located in the device API. The application improperly accepts hostnames or hardware serial numbers as valid authentication tokens in addition to the required device UUIDs. Because hostnames and serial numbers are often discoverable or guessable, an unauthenticated attacker can effectively spoof a legitimate iOS or iPadOS host. Successful exploitation allows the attacker to authenticate as a registered device, facilitating unauthorized access to sensitive device data. Furthermore, the attacker can influence device-scoped operations, such as triggering unauthorized software installations or migrating device management (MDM) configurations, posing a significant risk to fleet integrity and security posture.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability permits unauthorized access to sensitive device information and enables the execution of administrative actions across the fleet. Attackers may conduct unauthorized software deployments or move devices to malicious MDM environments, potentially leading to total loss of control over affected endpoints.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Fleet to version 4.87.0 or later to remediate the authentication bypass vulnerability in the device API (CVE-2026-103264).</li>
<li>Review access logs for the device API to identify unexpected authentication attempts originating from anomalous sources or those using non-UUID tokens if logging granularity permits.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>authentication-bypass</category><category>cve-2026-103264</category><category>mdm</category></item></channel></rss>