CVE WATCH / VULNERABILITY DETAIL
CVE-2026-103264
CRITICALCVSS 9.1NVD feed
Published 1 October 2026 · tracked since 2 October 2026
Description
Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS host
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog