{"id":"GHSA-q9c5-pp7m-fm2g","title":"Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs","summary":"Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs","severity":"medium","cvss":5.3,"cwe":["CWE-862"],"vendor":"fleetdm","product":"github.com/fleetdm/fleet/v4","ecosystem":"go","affected":["github.com/fleetdm/fleet/v4 < 4.87.0"],"patched":["github.com/fleetdm/fleet/v4 4.87.0"],"published":"2026-08-20","updated":"2026-08-20","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-q9c5-pp7m-fm2g","references":[{"url":"https://github.com/fleetdm/fleet/security/advisories/GHSA-q9c5-pp7m-fm2g"},{"url":"https://github.com/fleetdm/fleet/releases/tag/fleet-v4.87.0"},{"url":"https://github.com/advisories/GHSA-q9c5-pp7m-fm2g"}],"tags":["ghsa","go"],"ingestedAt":"2026-08-20T18:59:53.602Z","slug":"GHSA-q9c5-pp7m-fm2g","body":"## Overview\n\n### Summary\n\nTwo endpoints serving in-house iOS application packages and manifests in Fleet's enterprise tier are reachable without a hard-to-guess token in the URL, allowing an unauthenticated attacker who can reach the Fleet server to download an in-house IPA by guessing sequential title identifiers.\n\n### Impact\n\nBy design, Apple's `InstallEnterpriseApplication` MDM command requires that the manifest URL be reachable by the managed device without a Fleet session, so these endpoints cannot enforce session-based authentication. Fleet's legacy MDM installer path mitigates this by embedding a random, hard-to-guess token in the URL; the in-house iOS app endpoints (added later) were always intended to use the same time-limited-token pattern but the mitigation was not yet in place.\n\nThe result is read-only disclosure of in-house IPA binaries and their metadata (bundle identifier, version, name) that an operator has deployed through Fleet. This is enterprise-tier only — the free tier returns `fleet.ErrMissingLicense`. There is no privilege escalation, write access, or impact on hosts not managed by Fleet.\n\n### Workarounds\n\nIf an immediate upgrade is not possible:\n\n- Restrict network access to the Fleet server to trusted networks, as is typical for MDM deployments.\n- Remove in-house iOS apps that contain sensitive material from Fleet; in-house app IPAs are intentionally reachable by managed devices and should not be relied on as a confidential distribution channel.\n- Where available, configure CloudFront URL signing for software installers to limit the validity window of issued binary URLs.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\nEmail us at [security@fleetdm.com](mailto:security@fleetdm.com)\nJoin #fleet in [osquery Slack](https://join.slack.com/t/osquery/shared_invite/zt-h29zm0gk-s2DBtGUTW4CFel0f0IjTEw)\n\n### Credits\n\nWe thank @offset for responsibly reporting this issue.\n\n## Affected packages\n\n- `github.com/fleetdm/fleet/v4 < 4.87.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/fleetdm/fleet/v4 4.87.0`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}