Description
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
Published: 2026-05-07
Score: 7.2 High
EPSS: 4.9% Low
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper input validation flaw exists in Ivanti Endpoint Manager Mobile (EPMM) versions before 12.6.1.1, 12.7.0.1, and 12.8.0.1. A user who is already authenticated with administrative privileges can exploit this defect to execute arbitrary code on the device, leading to full system compromise. The weakness is identified as CWE‑20, indicating that the application does not properly validate or sanitize user-supplied data, thereby allowing an attacker to influence program behavior to their advantage.

Affected Systems

Affected are Ivanti Endpoint Manager Mobile deployments up to and including versions 12.6.1.1, 12.7.0.1, and 12.8.0.1. Any installation of these releases that allows remote administrative access is susceptible. Devices running newer releases are considered out of scope for this issue.

Risk and Exploitability

The CVSS score for this vulnerability is 7.2, classifying it as high severity. Exploitation requires remote authentication with administrative rights, meaning the attacker must first compromise or obtain valid credentials. The EPSS score of 5% indicates a very low likelihood of exploitation, though precise probability remains uncertain. The existence of the flaw in a product used for device management, combined with its inclusion in the CISA KEV catalog, indicates that it is actively exploited or is a high priority for attackers. Since remote code execution can occur from a remote context, the potential impact extends to all devices under the compromised administrative account and possibly to the broader network if lateral movement is possible.

Generated by OpenCVE AI on May 22, 2026 at 15:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Ivanti Endpoint Manager Mobile to the latest available version that addresses the input validation flaw.
  • If an immediate patch is unavailable, disable or tightly restrict remote administrative access until the update can be applied.
  • Conduct a swift internal audit of administrative credentials and enforce strong, multi‑factor authentication to reduce the risk of credential compromise.

Generated by OpenCVE AI on May 22, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 22 May 2026 15:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Ivanti Endpoint Manager Mobile Enables Remote Code Execution for Admins

Fri, 08 May 2026 15:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Improper Input Validation in Ivanti Endpoint Manager Mobile Pre‑12.6.1.1 Releases

Thu, 07 May 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.8.0.0:*:*:*:*:*:*:*

Thu, 07 May 2026 18:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Improper Input Validation in Ivanti Endpoint Manager Mobile Pre‑12.6.1.1 Releases
First Time appeared Ivanti
Ivanti endpoint Manager Mobile
Vendors & Products Ivanti
Ivanti endpoint Manager Mobile

Thu, 07 May 2026 17:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 07 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-05-07T00:00:00+00:00', 'dueDate': '2026-05-10T00:00:00+00:00'}


Thu, 07 May 2026 16:15:00 +0000

Type Values Removed Values Added
Description An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ivanti Endpoint Manager Mobile
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-05-08T03:55:38.232Z

Reserved: 2026-04-24T17:57:36.236Z

Link: CVE-2026-6973

cve-icon Vulnrichment

Updated: 2026-05-07T16:15:28.014Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-07T16:16:23.163

Modified: 2026-05-07T19:18:39.910

Link: CVE-2026-6973

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-22T15:30:38Z

Weaknesses