Fleet MDM Device API Authentication Bypass
Authentication bypass in Fleet MDM device API (CVSS 9.1). Versions before 4.87.0 accept hostnames and hardware serials as auth tokens. Patch: Fleet 4.87.0.
- Vendor
- FleetDM
- Product
- Fleet MDM
- CVSS
- 9.1
- EPSS (exploit probability)
- 0.3%
- Status
- patched
- Published
CVE-2026-103264 is an authentication bypass in the Fleet MDM device API. Affected builds accept hostnames and hardware serial numbers as valid authentication tokens alongside the intended device UUIDs. An unauthenticated attacker with knowledge of a target device’s hostname or serial number can authenticate as that device and access its telemetry. CVSS score: 9.1 (Critical), per NVD.
Affected products
Fleet MDM versions before 4.87.0. See the GitHub Security Advisory GHSA-vrc8-2wcx-327f for the full version matrix.
Exploitation status
No confirmed public exploitation as of October 3, 2026. The flaw is not listed on the CISA KEV catalog. Hostnames and hardware serials are frequently discoverable from asset management systems, DNS, or physical access, so the practical attack surface is wider than a credential-based authentication bypass would be.
Mitigation
Upgrade to Fleet 4.87.0 or later. The fix restricts device API authentication to device UUIDs only. Reviewing Fleet server access logs for device API calls authenticated with non-UUID patterns is advisable on affected versions.
