Improper Certificate Validation in Ivanti Endpoint Manager Mobile
CVE-2026-7821

7.4HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
7 May 2026

What is CVE-2026-7821?

Improper certificate validation in Ivanti Endpoint Manager Mobile (EPMM) can expose devices to unauthorized enrollment. Attackers can exploit this vulnerability to enroll a device from a limited set of unenrolled devices, potentially leading to information disclosure about the EPMM appliance and compromising the integrity of the enrolled device's identity. To safeguard against this vulnerability, affected users should update their EPMM to the latest versions: 12.6.1.1, 12.7.0.1, or 12.8.0.1.

Affected Version(s)

Endpoint Manager Mobile 12.6.1.1

Endpoint Manager Mobile 12.6.1.1

Endpoint Manager Mobile 12.7.0.1

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.