Sceawere

Vulnerability Detail

CVE-2026-101047UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated IPA Disclosure Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
14h ago
Vendor
fleetdm
Product
fleet
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Fleet before 4.87.0 does not protect the two endpoints that serve in-house iOS application packages and manifests (enterprise tier only) with the intended random, time-limited URL token. Because Apple's InstallEnterpriseApplication MDM command requires these URLs to be reachable without a Fleet session, they cannot rely on session-based authentication, and the missing token allows an unauthenticated attacker with network access to the Fleet server to download in-house IPA binaries and their metadata (bundle identifier, version, and name) by guessing sequential title identifiers. The impact is limited to read-only disclosure; there is no privilege escalation or write access, and the free tier is unaffected (it returns fleet.ErrMissingLicense).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-27T18:16:31.177Z",
  "pubdate": "2026-09-27T18:16:31.177Z",
  "executiveSummary": "A broken access control vulnerability exists in Fleet versions prior to 4.87.0 affecting enterprise-tier iOS application management. The vulnerability permits unauthenticated network actors to bypass intended security controls and access sensitive in-house iOS application packages (IPA files) and their associated metadata.\nThe flaw stems from the failure to implement mandated random, time-limited URL tokens on two specific endpoints responsible for serving enterprise iOS manifests and binaries. Because the Apple InstallEnterpriseApplication MDM protocol requires these endpoints to be accessible without a standard Fleet session, the absence of token-based authentication exposes these resources to unauthorized discovery and download.\nThe risk implication is restricted to information disclosure; an attacker can exfiltrate proprietary binaries and metadata such as bundle identifiers, versioning, and application naming schemes. The attack does not grant administrative control, write capabilities, or privilege escalation. The free tier of Fleet is explicitly unaffected as it lacks the corresponding enterprise features and will return a licensing error, limiting the scope to enterprise-licensed installations.",
  "technicalDetails": "The vulnerability resides in the application logic handling the dissemination of in-house iOS enterprise applications. Within Fleet's enterprise tier, the mechanism for distributing IPA files to managed devices via the MDM InstallEnterpriseApplication command relies on the Fleet server exposing specific endpoints to host binary and manifest files. Design specifications intended for these endpoints to be protected by ephemeral, cryptographically secure URL tokens that validate the legitimacy of a request without requiring an authenticated user session.\nThe root cause is a failure in access control implementation where these two endpoints fail to enforce the validation of the required random, time-limited URL tokens. Due to the requirements of the Apple MDM protocol, these URLs must be reachable by target devices without an existing authenticated session. Consequently, the absence of token validation allows any entity with network access to the Fleet server to interact with these endpoints directly.\nThe exploitation process follows a predictable, non-authenticated flow. Because the endpoints rely on sequential title identifiers to locate IPA files and metadata, an attacker can perform enumeration or 'guessing' of these identifiers. By iterating through potential sequence numbers, an attacker can systematically poll the vulnerable endpoints. If a valid identifier is identified, the server responds with the corresponding IPA binary and associated metadata (e.g., bundle identifiers, version strings, and internal naming conventions).\nBecause the endpoints are exposed over the network, no specific user privileges are required, and no prior session authentication is needed for successful exfiltration. The impact is limited to the read-only disclosure of the binary assets themselves. There is no mechanism within this flaw that facilitates remote code execution (RCE), persistent compromise, or write-based manipulation of the Fleet infrastructure. The scope of the vulnerability is strictly confined to the enterprise-tier modules; the open-source/free tier components do not contain the functional logic for hosting these enterprise IPA files and are therefore not susceptible to this unauthorized access, as they correctly return an error message indicating a missing license requirement when queried.\nThe vulnerability represents a significant lapse in the 'security-by-design' approach for the affected enterprise-managed assets, allowing for the unauthorized intelligence gathering of an organization's internal iOS application portfolio."
}
CVE-2026-101047: Unauthenticated IPA Disclosure Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere