---
id: CVE-2026-103264
title: >-
  Fleet versions before 4.87.0 contain an authentication bypass vulnerability in
  the device API that accepts hostnames and hardware serials as authentication
  tokens in addition to device UUIDs
summary: >-
  Fleet versions before 4.87.0 contain an authentication bypass vulnerability in
  the device API that accepts hostnames and hardware serials as authentication
  tokens in addition to device UUIDs. Unauthenticated attackers who know or
  guess t…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-287
vendor: fleetdm
product: fleet
affected:
  - fleet < 4.87.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:21.410'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103264'
references:
  - url: 'https://github.com/fleetdm/fleet/security/advisories/GHSA-vrc8-2wcx-327f'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/fleet-before-4.87.0-authentication-bypass-via-device-identifiers
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.806Z'
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-01T13:30:37.558254Z'
---

## Overview

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
