Improper Certificate Validation in Ivanti Endpoint Manager Mobile
CVE-2026-5787

8.9HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
7 May 2026

What is CVE-2026-5787?

An issue with certificate validation in Ivanti Endpoint Manager Mobile (EPMM) allows remote unauthenticated attackers to impersonate registered Sentry hosts, potentially leading to unauthorized access. This vulnerability impacts versions of EPMM prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1, making it crucial for users to secure their systems and update to the latest versions to mitigate risks.

Affected Version(s)

Endpoint Manager Mobile 12.8.0.1

Endpoint Manager Mobile 12.8.0.1

Endpoint Manager Mobile 12.7.0.1

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.