PatchSiren cyber security CVE debrief
CVE-2026-101047 fleetdm CVE debrief
CVE-2026-101047 debrief: Fleet server unauthenticated iOS app download via predictable URLs. The vulnerability allows attackers to access in-house iOS application packages and manifests without authentication, potentially leading to read-only disclosure of sensitive application data. Defenders managing Fleet servers, especially in enterprise tiers, should assess exposure and verify configurations to prevent unauthenticated iOS app downloads. This involves reviewing server configurations, assessing network access, and updating Fleet to version 4.87.0 or later.
- Vendor
- fleetdm
- Product
- fleet
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-27
- Original CVE updated
- 2026-09-27
- Advisory published
- 2026-09-27
- Advisory updated
- 2026-09-27
Who should care
Defenders managing Fleet servers, especially in enterprise tiers, should assess exposure and verify configurations to prevent unauthenticated iOS app downloads. This involves reviewing server configurations, assessing network access, and updating Fleet to version 4.87.0 or later. Additionally, defenders should review compensating controls for exposed systems, check relevant monitoring and logs, and track exceptions and retest remediated assets.
Why it matters
CVE-2026-101047 allows unauthenticated attackers to download in-house iOS application packages and manifests from Fleet servers, potentially leading to read-only disclosure of sensitive application data. Defenders managing Fleet servers, especially in enterprise tiers, should assess exposure and verify configurations to prevent unauthorized access.
- Read-only disclosure of in-house IPA binaries and metadata
- Potential for unauthorized access to sensitive application data
- Verification of Fleet server configurations and update to version 4.87.0 or later
Technical summary
Fleet before 4.87.0 does not protect endpoints serving in-house iOS application packages and manifests with a random, time-limited URL token. This allows unauthenticated attackers with network access to download IPA binaries and metadata by guessing sequential title identifiers. The impact is limited to read-only disclosure of in-house IPA binaries and metadata, including bundle identifier, version, and name. Defenders should prioritize verifying Fleet server configurations, especially for enterprise tiers, and assess exposure to potential unauthenticated iOS app downloads.
Defensive priority
Defenders should prioritize verifying Fleet server configurations, especially for enterprise tiers, and assess exposure to potential unauthenticated iOS app downloads.
Recommended defensive actions
- Verify Fleet server configurations, especially for enterprise tiers, to ensure the intended random, time-limited URL token is in use.
- Assess exposure to potential unauthenticated iOS app downloads by checking network access and sequential title identifier guessing.
- Update Fleet to version 4.87.0 or later to address the vulnerability.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE description notes that Fleet before 4.87.0 lacks a random, time-limited URL token for in-house iOS application packages and manifests, allowing unauthenticated attackers with network access to download IPA binaries and metadata by guessing sequential title identifiers.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-101047 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-101047
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-101047 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101047
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/fleetdm/fleet/security/advisories/GHSA-q9c5-pp7m-fm2g
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/fleet-before-4.87.0-unauthenticated-ios-app-download-via-predictable-urls
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.