CVE-2026-6973
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 (Secondary)
Description
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
Affected (3)
Products: Ivanti: Endpoint Manager Mobile
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.6.1.1 |
Related CWEs
CWE-15
External Control of System or Configuration Setting
One or more system settings or configuration elements can be externally controlled by a user.
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
References (2)
Source: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.