PT-2026-99565 · Fleet · Fleet
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Fleet versions prior to 4.87.0
Description
In the enterprise tier, two endpoints serving in-house iOS application packages and manifests lack the intended random, time-limited URL token protection. Since Apple's InstallEnterpriseApplication MDM command requires these URLs to be accessible without a Fleet session, session-based authentication is not used. This allows an unauthenticated attacker with network access to the Fleet server to download in-house IPA binaries and metadata, including the bundle identifier, version, and name, by guessing sequential title identifiers. The impact is limited to read-only disclosure.
Recommendations
Update to version 4.87.0 or later.
Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fleet