Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101047— Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs

Quick assessment

Affected
fleetdm fleet
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Fleet 4.87.0 之前的版本中,用于提供企业内部 iOS 应用包和清单文件的两个端点(仅限企业版)未按照预期使用随机、时效性的 URL 令牌进行保护。由于 Apple 的 InstallEnterpriseApplication MDM 命令要求这些 URL 必须能够在没有 Fleet 会话的情况下被访问,因此无法依赖基于会话的认证机制。缺失的令牌使得具有网络访问权限的未经身份验证的攻击者能够通过猜测连续的标题标识符,下载内部 IPA 二进制文件及其元数据(包括捆绑标识符、版本和名称)。该漏洞的影响仅限

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101047

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Fleet before 4.87.0 Unauthenticated iOS App Download via Predictable URLs
Source: CVE Program / CVE List V5
Vulnerability Description
Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot rely on session-based authentication, and the missing token allows an unauthenticated attacker with network access to the Fleet server to download in-house IPA binaries and their metadata (bundle identifier, version, and name) by guessing sequential title identifiers. The impact is limited to read-only disclosure; there is no privilege escalation or write access, and the free tier is unaffected (it returns fleet.ErrMissingLicense).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
fleetdm fleet 0 ~ 4.87.0 -

II. Public POCs for CVE-2026-101047

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101047

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101047 (1)

Other References for CVE-2026-101047 (1)

Same Patch Batch · fleetdm · 2026-09-27 · 3 CVEs total

CVE-2026-101045 8.0 HIGH Fleet Homebrew Cask OS Command Injection via Metadata
CVE-2026-101046 3.1 LOW Fleet before 4.89.0 SQL Injection via ORDER BY Activity Endpoints

IV. Related Vulnerabilities

V. Comments for CVE-2026-101047

No comments yet


Leave a comment