Cross-Site Scripting Vulnerability in BlackBerry UEM Management Console
CVE-2026-18084
8.6HIGH
What is CVE-2026-18084?
The BlackBerry UEM Management Console includes a vulnerability that allows attackers to exploit improper neutralization of input during web page generation, leading to Cross-Site Scripting (XSS). This flaw permits the execution of arbitrary scripts in the context of the user's browser, potentially compromising user data and security. Users of UEM versions 12.23.0 QF8 and earlier are particularly at risk, making it essential to update to a secure version to mitigate potential attacks.
Affected Version(s)
UEM 12.23.0 QF8 and earlier, 12.22.1 QF7 and earlier
