PT-2026-38456 · Ivanti · Epmm

Published

2026-05-07

·

Updated

2026-07-08

·

CVE-2026-6973

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager Mobile versions prior to 12.7.0.2 Ivanti Endpoint Manager Mobile versions prior to 12.8.0.3 Ivanti Endpoint Manager Mobile versions prior to 12.9.0.1
Description Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core, contains a configuration control issue resulting from improper input validation and failure to neutralize special elements. This flaw allows a remote authenticated attacker with administrator access to inject arbitrary Apache directives, leading to remote code execution (RCE) and the ability to execute arbitrary commands as root. The issue has been actively exploited in the wild, with over 850 servers reported as reachable from the internet, potentially exposing employee payroll records, device credentials, and sensitive files.
Recommendations Update Ivanti Endpoint Manager Mobile to version 12.6.1.1 or higher. Update Ivanti Endpoint Manager Mobile to version 12.7.0.1 or higher. Update Ivanti Endpoint Manager Mobile to version 12.8.0.1 or higher.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06623
BDU:2026-08922
CVE-2026-6973

Affected Products

Epmm