Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 01 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration. | |
| Title | Fleet before 4.87.0 Authentication Bypass via Device Identifiers | |
| First Time appeared |
Fleetdm
Fleetdm fleet |
|
| Weaknesses | CWE-287 | |
| CPEs | cpe:2.3:a:fleetdm:fleet:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fleetdm
Fleetdm fleet |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T13:32:04.417Z
Reserved: 2026-09-30T10:58:33.573Z
Link: CVE-2026-103264
Updated: 2026-10-01T13:30:43.190Z
Status : Awaiting Analysis
Published: 2026-10-01T11:17:21.410
Modified: 2026-10-01T15:09:04.013
Link: CVE-2026-103264
No data.
OpenCVE Enrichment
Updated: 2026-10-01T16:45:09Z