Some resolved issues in this release may have been addressed in a previous maintenance release.
Jamf Pro Server: Security Issues
Jamf provides the CVE-ID for security issues with high or critical severity when possible.
[PI135989] Fixed: A broken access control issue.
[PI140362] Fixed: A known vulnerability in a third-party library (CVE-2025-54988).
[PI140868] Fixed: A known vulnerability in a third-party library (CVE-2025-58057).
[PI141855] Fixed: A cross-site scripting (XSS) issue.
Jamf Pro Server
[PI101676] [PI-007477] Fixed: Jamf Pro reports app versions in an incorrect format for apps that have "Microsoft" in their names.
[PI109535] Fixed: After sending a remote command to unmanage a device, Jamf Pro does not display an option to manually mark a device as unmanaged. However, it still reports the device as unmanaged if the device acknowledges the command.
[PI109772] Fixed: When the Enable Jamf Pro to pass user information to Jamf Connect setting is enabled in Enrollment Customization settings, Jamf Pro fails to pass the SAML token information to Jamf Connect on newly enrolled computers, causing users to be prompted to log in an additional time.
[PI115997] Fixed: When using single sign-on authentication during user-initiated enrollment, end users may not be able to assign their device to a site.
[PI120239] Fixed: A failed declaration storage service (DSS) health check during Jamf Pro server startup can cause an unhandled exception that prevents the server from initializing completely.
[PI125518] Fixed: When parsing
SCEPChallengewebhook events, the webhook data does not include certain payload type attributes (e.g., com.apple.relay.managed).[PI132284] Fixed: When the Jamf management daemon is manually disabled using
launchctl unload -w, the disabled state persists in the macOSlaunchdoverride database even after running thejamf removeFrameworkcommand, causing certificate renewal failures and "connection invalidated" errors upon re-enrollment.[PI139061] Fixed: The bootstrap token can be removed during user-initiated enrollment and cause the device to lose its bootstrap token functionality.
[PI140237] Fixed: When password policy lockout settings are configured, Jamf Pro incorrectly displays an "invalid password" error on the password change page and disables the corresponding Jamf Pro user account.
[PI140917] Fixed: PreStage package installations fail when using AWS as the primary distribution point if the packages were uploaded in Jamf Pro 11.19.x or 11.20.x.
[PI141235] Fixed: Mobile device names fail to update when the Enforce Mobile Device Names option is enabled and devices are re-enrolled using a PreStage enrollment.
[PI143359] Fixed: The Content Security Policy may fail to update when a user's site is modified in Jamf Pro.
[PI143460] Fixed: When an iOS 26 or visionOS 26 device enrolled via Automated Device Enrollment is restored from an iCloud backup, the subsequent enrollment with Jamf Pro fails with a configuration download error because the
do_not_use_profile_from_backup configurationkey value is set tofalseand cannot be changed.[PI143818] Fixed: Jamf Pro fails to clear pending management commands sent via mass action when the Cancel all pending commands, except the following: option is selected.
[PI143843] Fixed: When opening a mobile device configuration profile's scope and returning to the Options tab, the Scope pane remains on the screen and blocks the view of the Options tab.
[PI143897] Fixed: Increased CPU usage may occur when the
InstallMediacommand is queued in large batches.