7.2

CVE-2026-6973

Warnung
Medienbericht
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IvantiEndpoint Manager Mobile Version < 12.6.1.1
IvantiEndpoint Manager Mobile Version12.7.0.0
IvantiEndpoint Manager Mobile Version12.8.0.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

07.05.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Schwachstelle

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

Beschreibung

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.13% 0.909
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
3c1d8aa1-5a33-4ea4-8992-aadd6440af75 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.