CVE-2026-6973

HIGH KEV

Ivanti Endpoint Manager Mobile - Improper Input Validation

Title source: rule
STIX 2.1

Description

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

Scores

CVSS v3 7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-05-07
VulnCheck KEV 2026-05-07
CWE
CWE-20
Status published
Products (3)
Ivanti/Endpoint Manager Mobile 12.6.1.1
Ivanti/Endpoint Manager Mobile 12.7.0.1
Ivanti/Endpoint Manager Mobile 12.8.0.1
Published May 07, 2026
KEV Added May 07, 2026
Tracked Since May 07, 2026