HIGH
CVE-2026-6973
CVSS
7.2
KEV
Description
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
Summary dbcve.org
This is an improper input validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM) affecting versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1. A remote attacker who has valid administrative credentials can exploit insufficient input validation to achieve arbitrary code execution on the vulnerable server.
Mitigation
Upgrade Ivanti EPMM to version 12.6.1.1, 12.7.0.1, 12.8.0.1 or later to remediate this vulnerability. If immediate patching is not possible, restrict administrative access to trusted networks and implement additional authentication controls.
Weakness (CWE)
CWE-20
Improper Input Validation
EPSS Score
34.45%
Probability of exploitation in next 30 days
98.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.