This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+11 more
Summary
AI summaryUpdates Bug fixes, BYOD, and profile-driven across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Fixes configuration profile being enqueued multiple times for a single host. Fixes configuration profile being enqueued multiple times for a single host. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes recovery lock password enforcement on BYOD macOS hosts, now skipped. Fixes recovery lock password enforcement on BYOD macOS hosts, now skipped. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes persistence of BYOD selection through IdP authentication. Fixes persistence of BYOD selection through IdP authentication. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes app installation failure for iOS/iPadOS manual (profile‑driven) BYOD enrollment, now installs to device. Fixes app installation failure for iOS/iPadOS manual (profile‑driven) BYOD enrollment, now installs to device. Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Allows App Store (VPP) and in-house app installation on iOS/iPadOS manual BYOD enrollment hosts. Allows App Store (VPP) and in-house app installation on iOS/iPadOS manual BYOD enrollment hosts. Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Full changelog
Bug fixes
- Fixed an issue where a configuration profile could be enqueued multiple times for a single host.
- Fixed recovery lock password being enforced on personally-owned (BYOD) macOS hosts, where it would always fail because personal enrollments have device lock rights stripped. These hosts are now skipped.
- Fixed a bug where a user's BYOD selection was not persisted through IdP authentication
- Fixed a bug where installing App Store (VPP) or in-house apps on an iOS/iPadOS host enrolled with the manual (profile-driven) BYOD enrollment profile failed while trying to look up a VPP user. These device-channel hosts now install apps to the device, the same as company-owned manual enrollment; user-scoped licensing is reserved for Account-Driven User Enrollment.
Upgrading
Please visit our update guide for upgrade instructions.
Documentation
Documentation for Fleet is available at fleetdm.com/docs.
Binary Checksum
SHA256
1adc9236a16edfdbaa321b3abcbea8fd93354bf348aa1984f1dbf41929f837be fleet_v4.88.1_linux.tar.gz
c0e6db9c7559487036572a292c8a4acb586fa041524d4e59d76730b4932a7375 fleetctl_v4.88.1_linux_amd64.tar.gz
3396a776f736513f511c7e8486838c0a4d6548d42329b66967d5abe33d8d1616 fleetctl_v4.88.1_linux_amd64.zip
6587d56fa84b8b93a25bc26551c86170de61a3ff00f7ad2745b841522fb9cff9 fleetctl_v4.88.1_linux_arm64.tar.gz
b79a62d090d562fd223b6674a9393f7276b5735fbae38ea5438927ba7a21554e fleetctl_v4.88.1_linux_arm64.zip
c308cce437f2cca7b24e27aa3501f8da5b072192f31ab68bd763dd33de7facad fleetctl_v4.88.1_macos.tar.gz
18256e18353febc7205cdaf5512ea820af282c0993ab8908704ee7a958814887 fleetctl_v4.88.1_macos.zip
b6028f87ca1c9f0302f0c8fa496de8f36afb06aab5838131befede5b20d95e93 fleetctl_v4.88.1_windows_amd64.tar.gz
6d67da0f5a97310abfd5772876d6baabe110bc8219e49e08cbea674f8086e60c fleetctl_v4.88.1_windows_amd64.zip
ff8334a6c8527a7d9ae069492aecf67403197ef4761e99c5526038adf39cc202 fleetctl_v4.88.1_windows_arm64.tar.gz
04db52fdd300cc55ffa94e84163551c0d8777414652ae995ab56fed778d1d873 fleetctl_v4.88.1_windows_arm64.zip
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Earlier breaking changes
- vfleet-v4.86.0 Required `--host` flag for `fleetctl get mdm-commands`; deprecated `GET /api/v1/fleet/commands` without a `host_identifier`.
- vfleet-v4.85.0 Enforced fleet name uniqueness across UI, API, and GitOps paths, returning 409 on conflicts
Beta — feedback welcome: [email protected]