Improper Input Validation in BlackBerry UEM Management Console Affects Multiple Versions
CVE-2026-18085

5.9MEDIUM

Key Information:

Vendor

Blackberry

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-18085?

The BlackBerry UEM Management Console is affected by a vulnerability due to improper input validation that could lead to arbitrary file downloads. This issue allows malicious actors to exploit the system, potentially resulting in denial of service conditions. Users running versions 12.23.0 QF8 and earlier are at risk, making it crucial to address this vulnerability promptly.

Affected Version(s)

UEM 12.23.0 QF8 and earlier, 12.22.1 QF7 and earlier

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christian Becker of Y-Security
.