PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-101047 fleetdm CVE debrief

CVE-2026-101047 debrief: Fleet server unauthenticated iOS app download via predictable URLs. The vulnerability allows attackers to access in-house iOS application packages and manifests without authentication, potentially leading to read-only disclosure of sensitive application data. Defenders managing Fleet servers, especially in enterprise tiers, should assess exposure and verify configurations to prevent unauthenticated iOS app downloads. This involves reviewing server configurations, assessing network access, and updating Fleet to version 4.87.0 or later.

Vendor
fleetdm
Product
fleet
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-27
Original CVE updated
2026-09-27
Advisory published
2026-09-27
Advisory updated
2026-09-27

Who should care

Defenders managing Fleet servers, especially in enterprise tiers, should assess exposure and verify configurations to prevent unauthenticated iOS app downloads. This involves reviewing server configurations, assessing network access, and updating Fleet to version 4.87.0 or later. Additionally, defenders should review compensating controls for exposed systems, check relevant monitoring and logs, and track exceptions and retest remediated assets.

Why it matters

CVE-2026-101047 allows unauthenticated attackers to download in-house iOS application packages and manifests from Fleet servers, potentially leading to read-only disclosure of sensitive application data. Defenders managing Fleet servers, especially in enterprise tiers, should assess exposure and verify configurations to prevent unauthorized access.

  • Read-only disclosure of in-house IPA binaries and metadata
  • Potential for unauthorized access to sensitive application data
  • Verification of Fleet server configurations and update to version 4.87.0 or later

Technical summary

Fleet before 4.87.0 does not protect endpoints serving in-house iOS application packages and manifests with a random, time-limited URL token. This allows unauthenticated attackers with network access to download IPA binaries and metadata by guessing sequential title identifiers. The impact is limited to read-only disclosure of in-house IPA binaries and metadata, including bundle identifier, version, and name. Defenders should prioritize verifying Fleet server configurations, especially for enterprise tiers, and assess exposure to potential unauthenticated iOS app downloads.

Defensive priority

Defenders should prioritize verifying Fleet server configurations, especially for enterprise tiers, and assess exposure to potential unauthenticated iOS app downloads.

Recommended defensive actions

  • Verify Fleet server configurations, especially for enterprise tiers, to ensure the intended random, time-limited URL token is in use.
  • Assess exposure to potential unauthenticated iOS app downloads by checking network access and sequential title identifier guessing.
  • Update Fleet to version 4.87.0 or later to address the vulnerability.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE description notes that Fleet before 4.87.0 lacks a random, time-limited URL token for in-house iOS application packages and manifests, allowing unauthenticated attackers with network access to download IPA binaries and metadata by guessing sequential title identifiers.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-101047 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-101047

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-101047 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101047

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.