CVE-2026-5788: Critical severity Ivanti Endpoint Manager Mobile (EPMM) vulnerability
Published May 7, 2026
·Updated
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.
Affected Software
4 affected components
Ivanti Endpoint Manager Mobile (EPMM)<12.6.1.1, <12.7.0.1, <12.8.0.1
Ivanti Endpoint Manager Mobile<12.6.1.1
Ivanti Endpoint Manager Mobile=12.7.0.0
Ivanti Endpoint Manager Mobile=12.8.0.0
Remediation
Event History
May 7, 2026
News Published
via BleepingComputer·03:20 PM
News Published
via BleepingComputer·03:22 PM
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-5788?
CVE-2026-5788 has been classified as a critical vulnerability due to improper access controls allowing remote unauthenticated attackers to invoke arbitrary methods.
2
How do I fix CVE-2026-5788?
To fix CVE-2026-5788, update Ivanti Endpoint Manager Mobile (EPMM) to versions 12.6.1.1, 12.7.0.1, or 12.8.0.1 or later.
3
What versions of Ivanti EPMM are affected by CVE-2026-5788?
CVE-2026-5788 affects Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1.
4
Can CVE-2026-5788 be exploited remotely?
Yes, CVE-2026-5788 can be exploited remotely by unauthenticated attackers.
5
What type of attacks can exploit CVE-2026-5788?
CVE-2026-5788 can be exploited for arbitrary method invocation attacks, potentially leading to unauthorized actions within the system.