{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-103264/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-103264"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Fleet (\u003c 4.87.0)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","cve-2026-103264","mdm"],"_cs_type":"threat","_cs_vendors":["FleetDM"],"content_html":"\u003cp\u003eFleet versions prior to 4.87.0 are affected by an authentication bypass vulnerability located in the device API. The application improperly accepts hostnames or hardware serial numbers as valid authentication tokens in addition to the required device UUIDs. Because hostnames and serial numbers are often discoverable or guessable, an unauthenticated attacker can effectively spoof a legitimate iOS or iPadOS host. Successful exploitation allows the attacker to authenticate as a registered device, facilitating unauthorized access to sensitive device data. Furthermore, the attacker can influence device-scoped operations, such as triggering unauthorized software installations or migrating device management (MDM) configurations, posing a significant risk to fleet integrity and security posture.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits unauthorized access to sensitive device information and enables the execution of administrative actions across the fleet. Attackers may conduct unauthorized software deployments or move devices to malicious MDM environments, potentially leading to total loss of control over affected endpoints.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Fleet to version 4.87.0 or later to remediate the authentication bypass vulnerability in the device API (CVE-2026-103264).\u003c/li\u003e\n\u003cli\u003eReview access logs for the device API to identify unexpected authentication attempts originating from anomalous sources or those using non-UUID tokens if logging granularity permits.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T12:41:31Z","date_published":"2026-10-01T12:41:31Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fleet-auth-bypass/","summary":"Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that allows unauthenticated attackers to spoof iOS or iPadOS devices using predictable identifiers.","title":"Authentication Bypass in Fleet Device API","url":"https://feed.craftedsignal.io/briefs/2026-10-fleet-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-103264","version":"https://jsonfeed.org/version/1.1"}