GHSA-q9c5-pp7m-fm2gMedium· 5.3▾ SunlitFleet: Unauthenticated download of in-house iOS app binaries via predictable URLs
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Two endpoints serving in-house iOS application packages and manifests in Fleet's enterprise tier are reachable without a hard-to-guess token in the URL, allowing an unauthenticated attacker who can reach the Fleet server to download an in-house IPA by guessing sequential title identifiers.
By design, Apple's InstallEnterpriseApplication MDM command requires that the manifest URL be reachable by the managed device without a Fleet session, so these endpoints cannot enforce session-based authentication. Fleet's legacy MDM installer path mitigates this by embedding a random, hard-to-guess token in the URL; the in-house iOS app endpoints (added later) were always intended to use the same time-limited-token pattern but the mitigation was not yet in place.
The result is read-only disclosure of in-house IPA binaries and their metadata (bundle identifier, version, name) that an operator has deployed through Fleet. This is enterprise-tier only — the free tier returns fleet.ErrMissingLicense. There is no privilege escalation, write access, or impact on hosts not managed by Fleet.
If an immediate upgrade is not possible:
If you have any questions or comments about this advisory:
Email us at [email protected] Join #fleet in osquery Slack
We thank @offset for responsibly reporting this issue.
github.com/fleetdm/fleet/v4 < 4.87.0Upgrade to a patched release:
github.com/fleetdm/fleet/v4 4.87.0Connected by shared product, vendor, weakness, or advisory.
GO-2026-6268NoneFleet: Unauthenticated download of in-house iOS app binaries via predictable URLs in github.com/fleetdm/fleet
CVE-2026-48786Medium· 6.5Fleet is an open-source device management platform built on osquery
GO-2026-6269NoneFleet: ORDER BY column injection on activity list endpoints in github.com/fleetdm/fleet
GHSA-rxhg-vcww-2mpwLow· 3.1Fleet: ORDER BY column injection on activity list endpoints
CVE-2026-46370Medium· 6.5Fleet is an open-source device management platform built on osquery
CVE-2026-46371Medium· 6.5Fleet is an open-source device management platform built on osquery