
CVE-2026-103264 hits fleetdm's Fleet, CVSS 9.1. Its device API accepts hostnames and hardware serials, not just UUIDs, as authentication tokens, so an attacker who knows or guesses one can authenticate as that iOS or iPadOS device, no real credential needed. VulnTracker recommends upgrading to Fleet 4.87.0 now, this lets an attacker read device data and trigger software installs or MDM migration. #Fleet #MDM #CVE #InfoSec


