PT-2026-38457 · Ivanti · Endpoint Manager Mobile

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-7821

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2026-7821

Affected Products

Endpoint Manager Mobile