Description
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
Published: 2026-09-08
Score: 8.8 High
EPSS: 1.0% Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The flaw is a missing authorization check in Ivanti Endpoint Manager Mobile that enables a remote authenticated attacker to raise their privileges to administrator. This elevates the attacker’s control over the device, allowing full configuration changes, installation of additional software, and potential compromise of confidential data. The weakness is a classic access control violation.

Affected Systems

Ivanti Endpoint Manager Mobile versions before 12.10.0.0, 12.9.0.2, and 12.8.0.4 are affected. The vulnerability exists in the vendor product’s native mobile management component.

Risk and Exploitability

The CVSS score of 8.8 marks the vulnerability as High, and the EPSS score of 1% indicates a low but non‑zero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, implying no known widespread attacks yet, but the attack vector is inferred to be remote after initial authentication. An attacker would need only to authenticate as a lower‑privilege user and then call privileged API endpoints that lack proper checks, subsequently assuming administrative rights.

Generated by OpenCVE AI on September 10, 2026 at 03:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Ivanti Endpoint Manager Mobile patch (12.10.0.0 or newer, or 12.9.0.3/12.8.0.5)
  • If an immediate patch is not possible, temporarily disable or restrict access to privileged API endpoints until a fix is deployed
  • Audit user access logs for unexpected privilege escalation and enforce the principle of least privilege

Generated by OpenCVE AI on September 10, 2026 at 03:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation due to Missing Authorization in Ivanti Endpoint Manager Mobile

Wed, 09 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.10.0.0:*:*:*:*:*:*:*

Tue, 08 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation due to Missing Authorization in Ivanti Endpoint Manager Mobile

Tue, 08 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti endpoint Manager Mobile
Vendors & Products Ivanti
Ivanti endpoint Manager Mobile

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ivanti Endpoint Manager Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-09T04:26:12.145Z

Reserved: 2026-08-04T15:48:06.352Z

Link: CVE-2026-18851

cve-icon Vulnrichment

Updated: 2026-09-08T14:37:10.451Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T15:18:42.533

Modified: 2026-09-09T13:59:45.970

Link: CVE-2026-18851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T04:00:06Z

Weaknesses