PT-2026-38456 · Ivanti · Epmm
Published
2026-05-07
·
Updated
2026-07-08
·
CVE-2026-6973
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ivanti Endpoint Manager Mobile versions prior to 12.7.0.2
Ivanti Endpoint Manager Mobile versions prior to 12.8.0.3
Ivanti Endpoint Manager Mobile versions prior to 12.9.0.1
Description
Ivanti Endpoint Manager Mobile (EPMM), formerly known as MobileIron Core, contains a configuration control issue resulting from improper input validation and failure to neutralize special elements. This flaw allows a remote authenticated attacker with administrator access to inject arbitrary Apache directives, leading to remote code execution (RCE) and the ability to execute arbitrary commands as root. The issue has been actively exploited in the wild, with over 850 servers reported as reachable from the internet, potentially exposing employee payroll records, device credentials, and sensitive files.
Recommendations
Update Ivanti Endpoint Manager Mobile to version 12.6.1.1 or higher.
Update Ivanti Endpoint Manager Mobile to version 12.7.0.1 or higher.
Update Ivanti Endpoint Manager Mobile to version 12.8.0.1 or higher.
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Epmm