A critical authentication bypass flaw has been disclosed and remediated in Fleet Device Management, the open-source endpoint observability, security management, and Mobile Device Management (MDM) platform widely deployed across enterprise cloud fleets to oversee millions of macOS, Windows, Linux, and iOS endpoints. Designated as CVE-2026-103264 and cataloged under GitHub Security Advisory GHSA-rmfg-c7hm-wv58 with a maximum CVSS v3.1 base score of 9.8 (Critical), the vulnerability allows unauthenticated remote actors to impersonate managed endpoints and trigger device-level administration actions using predictable hardware serial numbers.
Fleet in Modern Enterprise Endpoint & Zero Trust Architectures
Built on Facebook's open-source osquery standard, Fleet provides security operations centers (SOCs) with scheduled live telemetry, compliance baseline tracking, vulnerability assessment, and MDM orchestration. When corporate laptops and mobile devices enroll in Fleet, they communicate with the centralized server over the Device API (/api/v1/fleet/devices/*), which authenticates endpoints to deliver scheduled osquery queries, report software inventories, and receive administrative profiles.
Root Cause Analysis: Non-Secret Identifier Token Acceptance (CWE-287)
In Fleet versions prior to 4.87.0, the authentication middleware responsible for validating incoming device requests contained a critical logic flaw. While enrolled devices are provisioned with cryptographic session tokens and unique device UUIDs during MDM profile enrollment, the server's device lookup logic permitted multiple alternative identifier parameters:
// Vulnerable Authentication Logic in Fleet Server (< 4.87.0)
func (s *Service) AuthenticateDevice(ctx context.Context, token string) (*fleet.Host, error) {
// Expected: Validate cryptographically signed device secret token
host, err := s.ds.LoadHostByNodeKey(ctx, token)
if err == nil && host != nil {
return host, nil
}
// FATAL FLAW: Fallback to non-secret hardware identifiers!
// Accepts unauthenticated hardware serial number or device hostname:
if host, err = s.ds.LoadHostBySerial(ctx, token); err == nil && host != nil {
return host, nil // Grants full host session without password!
}
return nil, auth.ErrUnauthenticated
}
Because Apple hardware serial numbers (e.g., printed on device casings, visible in asset management spreadsheets, or predictable through sequential generation) are not confidential secrets, an unauthenticated attacker who knows or enumerates a target device's serial can supply it directly as an authentication bearer token.
Once authenticated as the target host, the attacker can submit requests to /api/v1/fleet/devices/{id}, exfiltrating the device's installed application inventory, network interface configurations, and logged-in user details. Furthermore, the attacker can trigger device-scoped MDM commands—including triggering enterprise software installations or re-pointing MDM enrollment profiles to malicious staging servers.
Device API Security State Comparison
| Authentication Method | Vulnerable Behavior (< 4.87.0) | Remediated Behavior (4.87.0+) |
|---|---|---|
| Hardware Serial Number | Accepted as full authentication token | Strictly rejected with 401 Unauthorized |
| Device Hostname | Accepted as fallback authentication token | Strictly rejected with 401 Unauthorized |
| Cryptographic Node Key | Validated if provided | Mandatory; must match high-entropy secret stored in OS keychain |
Remediation & Defense Actions
- Upgrade Fleet Server: Update all Fleet instances to version 4.87.0 or later immediately using official container images (
fleetdm/fleet:v4.87.0) or binary distributions. - Audit Device API Ingress Logs: Review HTTP access logs for requests to
/api/v1/fleet/devices/*where the authentication header length matches standard hardware serial format (10–12 alphanumeric characters) rather than 64-character node keys. - Rotate Fleet Enrollment Secrets: If serial number exposure is suspected in asset logs, rotate enterprise enrollment secrets and re-enroll sensitive mobile device profiles.



