CVE-2026-18085

MEDIUM

Improper Input Validation Leads to Arbitrary File Download and Potential Denial of Service in BlackBerry UEM

Title source: cna
STIX 2.1

Description

An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.

References (1)

Core 1

Scores

CVSS v4 5.9
EPSS 0.0021
EPSS Percentile 11.0%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-74
Status published
Products (1)
BlackBerry/UEM 12.23.0 QF8 and earlier, 12.22.1 QF7 and earlier
Published Jul 28, 2026
Tracked Since Jul 28, 2026