Jamf Pro Server: Security Issues
Jamf provides the CVE-ID for security issues with high or critical severity when possible.
[PI124081] Fixed: A known vulnerability in a third-party library (CVE-2024-47554).
This resolved issue is also included in Jamf Pro 11.17.1 or later.
[PI134886] Fixed: A known vulnerability in a third-party library (CVE-2025-29908).
[PI135185] Fixed: A broken access control issue in the Jamf Pro API.
[PI136052] Fixed: A known vulnerability in a third-party library (CVE-2025-48734).
Jamf Pro Server
[PI103287] [PI-009492] Fixed: If multiple duplicate objects exist in the user_objects database table, you cannot view, edit, or delete the associated object (e.g., a computer).
[PI103639] [PI-009599] Fixed: The MDM profile fails to renew on all enrolled devices after the Jamf Pro server URL is changed. All enrolled devices are affected because automatic MDM profile renewal is enabled by default in the MDM Profile Settings.
[PI111851] Fixed: Orphaned
RemoveApplicationandRemoveProfileremote commands can remain in device inventory after mobile devices are wiped or re-enrolled.[PI112839] Fixed: Using the Return to Service option with the
Erase Devicecommand in the Jamf Pro API results in Jamf Pro sending aRemove MDM Profilecommand to devices in scope. This disconnects the devices from the Wi-Fi network.-
[PI115704] Fixed: If a process state is not present for a volume purchase location, the volume purchase location page fails to load.
[PI117426] [PI125920] Fixed: When a Mac computer is re-enrolled using the
sudo profiles renew -type enrollmentcommand, the bootstrap token fails to escrow to Jamf Pro because thecom.apple.mdm.bootstraptokenserver capability declaration required for bootstrap token functionality is missing from the MDM profile.[PI117514] Fixed: Sending the Renew MDM Profile command to mobile devices may fail due to a missing or blank invitation string in a database table.
[PI118404] Fixed: The JSON web token required to authenticate package downloads sometimes fails to renew, causing package downloads to fail.
[PI122875] Fixed: Recovery Lock codes in the Jamf Pro database are sometimes incorrect, causing looping behaviors or failures when attempting to unlock a locked device.
[PI125968] Fixed: Devices enrolled via Automated Device Enrollment fail to renew MDM profiles if unassigned from their original PreStage enrollment.
[PI134544] Fixed: Usernames are not recorded in the jssaccess.log file after users log out of Jamf Pro.
[PI135204] Fixed: After device re-enrollment, some configuration profiles may fail to install automatically even when properly scoped to the device.
This resolved issue is also included in Jamf Pro 11.17.1 or later.
[PI135884] Fixed: Smart user groups that use excluding criteria (e.g., "is not", "not like", "does not match regex") to match roster data fail to match users with no associated Apple School Manager roster data due to a smart group calculation error.
This resolved issue is also included in Jamf Pro 11.17.1 or later.
[PI135942] Fixed: (Third-party issue) An update to Log4j introduced a threading issue that could cause silent thread failures during server operations when multiple threads attempt to modify logger levels or create new loggers simultaneously.
This resolved issue is also included in Jamf Pro 11.17.1 or later.
[PI135944] Fixed: When "Last Reported IP Address" is selected as a display field for an advanced computer search, the display field fails to appear in the results.
This resolved issue is also included in Jamf Pro 11.17.1 or later.