PT-2026-5358 · Ivanti · Ivanti Endpoint Manager Mobile

Published

2026-01-29

·

Updated

2026-05-08

·

CVE-2026-1340

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager Mobile (affected versions not specified)
Description A code injection issue in Ivanti Endpoint Manager Mobile allows unauthenticated remote attackers to achieve remote code execution. This is caused by improper management of code generation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-01123
CVE-2026-1340

Affected Products

Ivanti Endpoint Manager Mobile