CVE-2026-7821

HIGH

Ivanti Endpoint Manager Mobile < 12.6.1.1, < 12.7.0.1, < 12.8.0.1 - Unauthenticated Improper Certificate Validation

Title source: llm
STIX 2.1

Description

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

Scores

CVSS v3 7.4
EPSS 0.0006
EPSS Percentile 18.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (6)
Ivanti/Endpoint Manager Mobile 12.6.1.1
Ivanti/Endpoint Manager Mobile 12.7.0.1
Ivanti/Endpoint Manager Mobile 12.8.0.1
ivanti/endpoint_manager_mobile 12.7.0.0
ivanti/endpoint_manager_mobile 12.8.0.0
ivanti/endpoint_manager_mobile < 12.6.1.1
Published May 07, 2026
Tracked Since May 07, 2026