HIGH

CVE-2026-6973

Ivanti Endpoint Manager Mobile 2026-05-07 CVSS v3.1
CVSS
7.2
KEV

Description

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

Summary dbcve.org

This is an improper input validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM) affecting versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. A remote attacker who has valid administrative credentials can exploit insufficient input validation to achieve arbitrary code execution on the vulnerable server.

Mitigation

Upgrade Ivanti EPMM to version 12.6.1.1, 12.7.0.1, 12.8.0.1 or later to remediate this vulnerability. If immediate patching is not possible, restrict administrative access to trusted networks and implement additional authentication controls.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

34.45%
Probability of exploitation in next 30 days
98.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE