CVE-2026-10727: OS Command Injection
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti EPMMto a version that resolves this vulnerability.Fixed in 12.9.0.1 - Upgrade
Upgrade
Ivanti EPMMto a version that resolves this vulnerability.Fixed in 12.8.0.3 - Upgrade
Upgrade
Ivanti EPMMto a version that resolves this vulnerability.Fixed in 12.7.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10727?
CVE-2026-10727 has a severity score of 7.2, categorized as high.
What type of vulnerability is CVE-2026-10727?
CVE-2026-10727 is an OS command injection vulnerability.
How does CVE-2026-10727 affect Ivanti EPMM?
CVE-2026-10727 allows a remote authenticated attacker to execute arbitrary commands as root in Ivanti EPMM versions before the mentioned patched releases.
How do I fix CVE-2026-10727?
To fix CVE-2026-10727, update Ivanti EPMM to version 12.9.0.1, 12.8.0.3, or 12.7.0.2 or later.
Who can exploit CVE-2026-10727?
CVE-2026-10727 can be exploited by remote authenticated attackers.