CVE-2026-5786
high
CVSS v3
8.8
CVSS v2
—
VIR risk
8.8
Description
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: 3c1d8aa1-5a33-4ea4-8992-aadd6440af75 — https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ivanti | endpoint_manager_mobile | {"endExcluding":"12.6.1.1"} | 12.6.1.1 |
| ivanti | endpoint_manager_mobile | 12.7.0.0 | |
| ivanti | endpoint_manager_mobile | 12.8.0.0 | |
References
CWEs
CWE-284
Verify integrity in audit chain (admin only). AS-IS.