Jamf Pro 11.31.1: qualify server fixes before restoring the MDM control plane to trust
Jamf Pro 11.31.1 fixes two XSS issues, updates Spring Framework in its installers, and documents a defect affecting redistribution of a shared iOS device compliance configuration. IT teams should treat this release as maintenance of the MDM control plane, with backup, qualification, and evidence of correct operation after the upgrade.
1. What Jamf documents precisely
The official Jamf Pro 11.31.1 notes list two fixed cross-site scripting issues, referenced as PI186191 and PI208395. Jamf also states that the installers include Spring Framework 6.2.18, which addresses multiple vulnerabilities, including CVE-2026-41842 and CVE-2026-41855.
On this page, Jamf provides no exploitation scenario, CVSS score, or indication of active exploitation for the two XSS issues. Teams should not manufacture a severity rating: the maintenance decision must combine actual server exposure, the administration architecture, and the organization's vulnerability-management policy.
2. The shared iOS fix that should not be overlooked
The same note explains that after a custom PLIST used for shared iOS device compliance was modified, Jamf Pro could fail to redistribute the updated configuration to targeted devices until they were re-enrolled. Jamf says PI148391 was already fixed in Jamf Pro 11.31.0 but had been omitted from its notes.
This clarification changes the required test. Confirming that the profile exists in the console is not enough. Teams should modify a setting within a pilot scope, confirm redistribution without re-enrollment, and then verify the state actually received by devices.
3. What does this announcement change for a Belgian or French organization?
For an SMB whose Jamf environment is operated by a partner, the immediate questions are the tenant or server version, the maintenance window, and evidence from post-upgrade controls. For a mid-sized company, large enterprise, or public administration in Belgium or France, the issue is broader: Jamf Pro distributes policies, holds inventory data, and controls devices. Its control plane must therefore be protected as sensitive infrastructure.
Self-hosted installations should examine interface exposure, backups, dependencies, and rollback. Jamf Cloud environments should verify the rollout schedule that applies to their tenant and focus testing on business workflows, without assuming that a server-side fix automatically validates profiles and integrations.
4. Underside analysis: test the trust chain, not only the version
Our view is that a successful MDM update is more than a build number. The chain to validate runs from administrator authentication to APNs delivery, then profile redistribution, inventory, and compliance integrations. The shared iOS defect illustrates the potential gap between an object correctly recorded in Jamf and its real application on the endpoint.
This qualification complements the work on Mac enrollment with Jamf Pro 11.31 and OIDC authentication for Jamf Pro administrators. Together, these controls cover access to the management plane, device entry, and effective configuration delivery.
5. Recommended upgrade plan
- Identify the version, hosting model, exposure, and maintenance window for every instance.
- Read the 11.31 and 11.31.1 notes, verify prerequisites, and back up the database and items required by the Jamf runbook.
- Qualify administrator access, roles, and exposed interfaces before and after the upgrade.
- Test ADE, MDM commands, inventory, apps, profiles, APNs, and compliance integrations on a pilot group.
- For affected shared iPhones or iPads, modify a pilot PLIST and prove redistribution without re-enrollment.
- Record the version, results, anomalies, and rollout decision in the change register.
Goal: patch the Jamf server without losing sight of its essential function—applying and proving the fleet's actual management state.
Qualify your Jamf upgradeOfficial source: Jamf Pro 11.31.1 — Resolved Issues (accessed August 26, 2026).