Improper Input Validation in Ivanti Endpoint Manager Mobile
CVE-2026-6973

7.2HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
7 May 2026

Badges

📰 News Worthy

What is CVE-2026-6973?

CVE-2026-6973 is a vulnerability found in Ivanti Endpoint Manager Mobile (EPMM), a product designed to provide mobile device management solutions for organizations. The vulnerability arises from improper input validation within the software, which affects versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. A remotely authenticated user with administrative privileges can exploit this flaw to achieve remote code execution, potentially allowing attackers to manipulate system functionalities or access sensitive data. The significance of this vulnerability is heightened as Ivanti EPMM is commonly used in enterprise environments to manage and secure mobile devices, making its exploitation highly detrimental.

Potential impact of CVE-2026-6973

  1. Remote Code Execution: The primary risk associated with CVE-2026-6973 is the potential for remote code execution. This enables an attacker to execute arbitrary code on the affected system, which can lead to unauthorized control over the mobile management platform and any devices managed through it.

  2. Data Breach Risks: By exploiting the vulnerability, malicious actors could gain access to confidential user data and sensitive organizational information stored within the EPMM platform. This poses risks of data leaks, compliance violations, and damage to reputation.

  3. Compromise of Mobile Security: Given that EPMM is responsible for managing mobile devices, successful exploitation could lead to broader mobile security breaches. Attackers could manipulate device policies, distribute malicious applications, or disable security measures, further endangering the organization's overall security posture.

Affected Version(s)

Endpoint Manager Mobile 12.6.1.1

Endpoint Manager Mobile 12.6.1.1

Endpoint Manager Mobile 12.7.0.1

News Articles

Ivanti warns of new EPMM flaw exploited in zero-day attacks

Ivanti warned customers today to patch a high-severity remote code execution vulnerability in Endpoint Manager Mobile (EPMM) exploited in zero-day attacks.

3 hours ago

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

.