CVE-2026-18851: High severity Ivanti Ivanti Endpoint Manager Mobile vulnerability
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Manager Mobileto a version that resolves this vulnerability.Fixed in 12.10.0.0 - Upgrade
Upgrade
Ivanti Endpoint Manager Mobileto a version that resolves this vulnerability.Fixed in 12.9.0.2 - Upgrade
Upgrade
Ivanti Endpoint Manager Mobileto a version that resolves this vulnerability.Fixed in 12.8.0.4
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker who is already authenticated to Ivanti Endpoint Manager Mobile can exploit the missing authorization check. No user interaction is required.
Which versions need to be remediated?
Versions before 12.10.0.0, 12.9.0.2, and 12.8.0.4 are affected. Upgrade to the applicable listed version or later.
What is the impact if exploitation succeeds?
An authenticated attacker can escalate their privileges to administrator. The vulnerability is rated high with impacts to confidentiality, integrity, and availability.