Some resolved issues in this release may have been addressed in a previous maintenance release.
Jamf Pro Server: Security Issues
Jamf provides the CVE-ID for security issues with high or critical severity when possible.
[PI17895] Fixed: A sensitive information disclosure issue.
[PI186191] Fixed: A cross-site scripting (XSS) issue.
[PI208395] Fixed: A cross-site scripting (XSS) issue.
[PI209382] Fixed: The Jamf Pro installers include Spring Framework 6.2.18, which includes multiple vulnerabilities, including CVE-2026-41842 and CVE-2026-41855.
Jamf Pro Server
[PI-1332] Fixed: When an existing device is re-enrolled using Automated Device Enrollment or user-initiated enrollment, Jamf Pro updates every device linked to that device's user and recalculates smart group membership before responding to the enrollment request. The extra processing can exceed the 60-second enrollment timeout, causing the device to display an "Enrolling with management server failed" error during Setup Assistant.
[PI110307] Fixed: The Jamf Pro interface does not display a New button to create a webhook for some Jamf Pro accounts, even if those accounts have the proper privileges.
[PI148391] Fixed: After modifying the custom configuration PLIST for iOS shared device compliance, Jamf Pro fails to redistribute the updated configuration to target devices until they are re-enrolled.
Note:This issue was resolved in Jamf Pro 11.31.0 and was inadvertently omitted from those release notes.
[PI173119] [PI173120] Fixed: The Jamf Pro server may experience performance issues when sending MDM commands containing a large binary payload, such as a wallpaper image.
[PI200840] Fixed: Upgrading to Jamf Pro 11.27.0 through 11.31.x deletes Automated Device Enrollment account details for instances that share an MDM server in Apple Business or Apple School Manager.