CVE-2026-6973: Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
A configuration control vulnerability in the Ivanti Endpoint Manager Mobile before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to inject arbitrary Apache directives, leading to remote code execution.
Other sources
Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6973?
CVE-2026-6973 is considered a critical vulnerability due to its potential for remote code execution by an authenticated user with administrative access.
How do I fix CVE-2026-6973?
To mitigate CVE-2026-6973, upgrade Ivanti EPMM to versions 12.6.1.2, 12.7.0.2, or 12.8.0.2 or later.
Who is affected by CVE-2026-6973?
CVE-2026-6973 affects users of Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1.
What are the implications of CVE-2026-6973?
Exploitation of CVE-2026-6973 may allow attackers to execute arbitrary code remotely within the affected environment.
Is there a workaround for CVE-2026-6973?
There are no confirmed effective workarounds for CVE-2026-6973 other than upgrading to the patched versions.