Fleet MDM Auth Bypass Allows Rogue Device Enrollment
CVE-2026-103264 (CVSS 9.1) in Fleet MDM before 4.87.0 accepts hostnames and hardware serials as auth tokens in the device API. Patch available: Fleet 4.87.0.

CVE-2026-103264, CVSS 9.1. Fleet MDM versions before 4.87.0. The device API accepts hostnames and hardware serial numbers as authentication tokens in addition to the intended device UUIDs. An unauthenticated attacker who knows a target device’s hostname or serial can authenticate as that device. Patch available.
The flaw
Fleet’s device API is meant to accept device UUIDs as authentication tokens. In affected builds, the API also treats hostnames and hardware serial numbers as valid credentials. An attacker with network access to the Fleet server and a known hostname or serial number can authenticate as any matching device without a UUID.
Full details in GitHub Security Advisory GHSA-vrc8-2wcx-327f. NVD record: CVE-2026-103264. CVSS: 9.1 Critical.
Exposure
Fleet’s device API carries the data enrolled endpoints report back to the server: hardware inventory, installed software, security policy compliance status, and configuration details. An attacker authenticated as a target device can query that telemetry without presenting a valid enrollment token.
Public exploitation: unconfirmed as of this report. The attack surface is wider than a standard credential bypass, though. Hostnames and hardware serials are not secrets. They appear routinely in DNS, asset management databases, IT ticketing systems, and on physical device labels. In environments where the Fleet server is accessible from broader internal networks, knowledge of a hostname is a realistic prerequisite.
Patch
Fleet 4.87.0 restricts device API authentication to device UUIDs. The vendor advisory recommends upgrading; no workaround is listed as an equivalent substitute.
Fleet server access logs on older builds are worth reviewing for device API calls authenticated with non-UUID patterns before applying the patch.
Vendor advisory: GHSA-vrc8-2wcx-327f. NVD: CVE-2026-103264.
Also this week: a critical auth bypass in Cisco SD-WAN Manager reached the CISA KEV catalog on October 1, and critical flaws in Dell Container Storage Modules allowed unauthenticated admin access to Kubernetes clusters.
- [ CRITICAL ]CVE-2026-103264Fleet MDM Device API Authentication Bypass
Found this useful? Share it.


