CVE-2026-18851

Summary

Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.

Affected Software

VendorProductVersion RangeStatus
IvantiEndpoint Manager Mobile12.10.0.0unaffected
IvantiEndpoint Manager Mobile12.9.0.2unaffected
IvantiEndpoint Manager Mobile12.8.0.4unaffected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References