CVE-2026-6973
HIGH KEVIvanti Endpoint Manager Mobile - Improper Input Validation
Title source: ruleDescription
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
References (1)
Core 1
Scores
CVSS v3
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
no
Technical Impact
total
Details
CISA KEV
2026-05-07
VulnCheck KEV
2026-05-07
CWE
CWE-20
Status
published
Products (3)
Ivanti/Endpoint Manager Mobile
12.6.1.1
Ivanti/Endpoint Manager Mobile
12.7.0.1
Ivanti/Endpoint Manager Mobile
12.8.0.1
Published
May 07, 2026
KEV Added
May 07, 2026
Tracked Since
May 07, 2026