PT-2026-5357 · Ivanti · Ivanti Endpoint Manager Mobile
Published
2026-01-29
·
Updated
2026-07-08
·
CVE-2026-1281
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ivanti Endpoint Manager Mobile (affected versions not specified)
Description
An unauthenticated remote code execution issue exists due to improper control of code generation, specifically a server-side template injection. Remote attackers can abuse a template rendering workflow exposed via the management interface to execute arbitrary OS-level commands in the context of the service. This can lead to full server compromise, takeover of the MDM infrastructure, and exposure of stored credentials or secrets. In a real-world incident, attackers linked to UNC5221 allegedly exploited this issue to steal sensitive data—including full names, phone numbers, email addresses, device identifiers, and geolocation—from the mobile phones of Belgian State Security Service employees.
Recommendations
Apply the security updates for Ivanti Endpoint Manager Mobile as published in the official advisory channel.
Restrict access to management ports (typically 443 and 8443) to VPN, jump hosts, and allowlisted IPs only.
Disable non-essential template rendering features or endpoints as a temporary containment measure.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ivanti Endpoint Manager Mobile