CVE-2026-18085

Summary

An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.

Affected Software

VendorProductVersion RangeStatus
BlackBerryUEM12.23.0 QF8 and earlier, 12.22.1 QF7 and earlieraffected

Weaknesses

  • CWE-74: CWE-74: Improper Neutralization of Special Elements in Output (Injection)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References