CVE-2026-5787

8.9

Ivanti · Endpoint Manager Mobile (EPMM)

An improper certificate validation vulnerability in Ivanti EPMM allows remote unauthenticated attackers to impersonate Sentry hosts and obtain valid client certificates.

Executive summary

An improper certificate validation flaw in Ivanti Endpoint Manager Mobile (EPMM) allows remote unauthenticated attackers to impersonate registered Sentry hosts, posing a severe risk to organizational infrastructure.

Vulnerability

This is an improper certificate validation issue categorized as CWE-295. A remote unauthenticated attacker can exploit this flaw over the network with high complexity and no user interaction required.

Business impact

A successful exploit could allow malicious actors to obtain valid CA-signed client certificates and impersonate registered Sentry hosts, leading to unauthorized access to sensitive internal communications and enterprise resources. While the CVSS score is 8.9, placing it in the high severity range, the potential for total technical impact and compromise of trust boundaries elevates the organizational risk.

Remediation

Immediate Action: Update Ivanti Endpoint Manager Mobile (EPMM) to version 12.8.0.1, 12.7.0.1, 12.6.1.1, or later as specified in the vendor advisory.

Proactive Monitoring: Monitor network and access logs for anomalous registration attempts or suspicious certificate requests originating from unverified Sentry hosts.

Compensating Controls: Implement strict network segmentation around EPMM deployment environments and enforce strict monitoring on certificate authority issuance pipelines.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high severity and the potential for severe operational disruption through identity spoofing, administrators must treat this advisory with urgency. Apply the appropriate vendor security updates immediately to mitigate the risk of unauthorized certificate issuance and host impersonation.

More Ivanti CVEs

Sources