CVE-2026-5786

8.8

Ivanti · Endpoint Manager Mobile (EPMM)

An improper access control vulnerability in Ivanti EPMM allows a remote authenticated attacker to gain administrative access.

Executive summary

An improper access control vulnerability in Ivanti Endpoint Manager Mobile allows remote authenticated attackers to achieve total system compromise, posing a severe threat to enterprise infrastructure.

Vulnerability

This is an improper access control vulnerability, classified under CWE-284, affecting Ivanti Endpoint Manager Mobile. The flaw allows a remote attacker with low-level authenticated privileges and no user interaction to escalate privileges and gain full administrative access.

Business impact

A successful exploitation of this vulnerability can lead to complete confidentiality, integrity, and availability loss across the affected endpoint management infrastructure. Attackers who gain administrative access can manipulate managed devices, deploy malicious configurations, or exfiltrate sensitive enterprise data. The high CVSS score of 8.8 reflects the catastrophic impact of administrative takeover, justifying immediate and prioritized remediation.

Remediation

Immediate Action: Update Ivanti Endpoint Manager Mobile to version 12.6.1.1, 12.7.0.1, 12.8.0.1, or later versions where the access control flaw is resolved.

Proactive Monitoring: Review administrative audit logs regularly for unexpected privilege escalation events, unauthorized administrative actions, or anomalous login patterns from low-privileged accounts.

Compensating Controls: Restrict network access to the EPMM administration interfaces to trusted management subnets and enforce multi-factor authentication for all user sessions to minimize unauthorized access risks.

Exploitation status

Public Exploit Available: false

Analyst recommendation

This vulnerability represents a critical risk to organizational asset management due to the potential for complete administrative takeover by authenticated attackers. Security teams must prioritize applying the vendor security updates immediately to eliminate the underlying access control flaw and secure the environment.

More Ivanti CVEs

Sources