Sceawere

Vulnerability Detail

CVE-2026-18851UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ivanti EPMM Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
3h ago
Vendor
Ivanti
Product
Endpoint Manager Mobile
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-08T15:18:42.533Z",
  "pubdate": "2026-09-08T15:18:42.533Z",
  "executiveSummary": "This vulnerability involves a missing authorization flaw within Ivanti Endpoint Manager Mobile (EPMM) that permits a remote authenticated attacker to perform a privilege escalation attack.\nBy bypassing authorization controls, an attacker can elevate their existing account permissions to administrative levels.\nThe flaw affects Ivanti Endpoint Manager Mobile versions prior to 12.10.0.0, 12.9.0.2, and 12.8.0.4.\nSuccessful exploitation poses a critical risk to the confidentiality, integrity, and availability of the managed mobile environment, as an attacker with administrative privileges gains full control over the platform, managed devices, and security configurations.\nExploitation requires the attacker to already possess a valid, authenticated user session within the target system, after which they can leverage the lack of authorization checks to execute unauthorized administrative actions.\nOrganizations using these affected versions should prioritize updates to the specified patched releases to mitigate the risk of unauthorized administrative access.",
  "technicalDetails": "The vulnerability resides in the authorization logic of Ivanti Endpoint Manager Mobile (EPMM), specifically stemming from a failure to perform adequate validation of user permissions during sensitive operations. This constitutes a missing authorization defect, preventing the system from confirming that an authenticated user is authorized to perform administrative tasks.\nThe root cause is a deficiency in the server-side access control mechanisms. In affected versions of Ivanti EPMM, certain administrative-level endpoints or functions fail to verify the authorization context of the requester. Consequently, while the application correctly validates the authenticity of the user session, it neglects to enforce the principle of least privilege, allowing any successfully authenticated user—regardless of their assigned role—to access or manipulate administrative functions.\nThe exploitation flow begins with a remote attacker establishing a legitimate, authenticated session as a low-privileged user within the target Ivanti EPMM environment. Once authenticated, the attacker identifies the targeted administrative endpoints that lack authorization checks. The attacker then crafts specific requests—typically HTTP requests directed at the backend administrative API or management console endpoints—that would otherwise be restricted to administrative accounts. Because the application fails to perform a secondary validation of the requester's authorization level, the server processes these requests as if they originated from a system administrator.\nThe post-exploitation impact is severe. Upon successful elevation to administrative privileges, the attacker gains full control over the Ivanti EPMM instance. This includes, but is not limited to, the ability to manage mobile device configurations, access sensitive device information, deploy malicious profiles or applications to managed endpoints, modify global security policies, and potentially exfiltrate sensitive organizational data. By gaining administrative control, the attacker can effectively subvert the entire mobile device management architecture, turning a managed security environment into a vector for further organizational compromise.\nAffected software versions include all iterations of Ivanti Endpoint Manager Mobile prior to the versions 12.10.0.0, 12.9.0.2, and 12.8.0.4. Given the nature of this vulnerability, it is classified as a remote, authenticated privilege escalation, meaning that network connectivity to the management interface is a prerequisite for the attacker to initiate the exploitation sequence."
}
CVE-2026-18851: Ivanti EPMM Privilege Escalation Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere