PT-2026-5358 · Ivanti · Ivanti Endpoint Manager Mobile

Published

2026-01-29

·

Updated

2026-02-02

·

CVE-2026-1340

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager Mobile versions 12.7.x and earlier
Description A code injection exists in Ivanti Endpoint Manager Mobile that allows attackers to achieve unauthenticated remote code execution. This means attackers can run arbitrary code without needing to log in. The issue allows for the execution of code on affected systems.
Recommendations Update Ivanti Endpoint Manager Mobile to a version newer than 12.7.x.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-1340

Affected Products

Ivanti Endpoint Manager Mobile