Ivanti Endpoint Manager Mobile

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Ivanti Endpoint Manager Mobile.

By the Year

In 2026 there have been 2 vulnerabilities in Ivanti Endpoint Manager Mobile with an average score of 9.8 out of ten. Last year, in 2025 Endpoint Manager Mobile had 8 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Endpoint Manager Mobile in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 3.33.




Year Vulnerabilities Average Score
2026 2 9.80
2025 8 6.47
2024 8 7.85
2023 5 9.45

It may take a day or so for new Endpoint Manager Mobile vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Ivanti Endpoint Manager Mobile Security Vulnerabilities

CVE-2026-1340: unauth RCE via code injection in Ivanti Endpoint Manager Mobile
CVE-2026-1340 9.8 - Critical - January 29, 2026

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Code Injection

CVE-2026-1281: Code Injection in Ivanti Endpoint Manager Mobile (Unauth RCE)
CVE-2026-1281 9.8 - Critical - January 29, 2026

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Code Injection

Path Traversal: Ivanti EPMM <12.6.0.2 Admin Path Write Vulnerability
CVE-2025-10986 4.7 - Medium - October 14, 2025

Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.

Directory traversal

OS Command Injection in Ivanti EPMM <=12.6.0.2 Admin Panel
CVE-2025-10985 7.2 - High - October 14, 2025

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Shell injection

Ivanti EPMM OS Command Injection (Admin Panel) <12.6.0.2,12.5.0.4,12.4.0.4
CVE-2025-10243 7.2 - High - October 14, 2025

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Shell injection

Remote CMD Injection in Ivanti EPMM Admin (12.6.0.2)
CVE-2025-10242 7.2 - High - October 14, 2025

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Shell injection

OS Command Injection CVE-2025-6771 in Ivanti EPMM <12.5.0.2 (12.4.0.3,12.3.0.3)
CVE-2025-6771 - July 08, 2025

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution

Shell injection

CVE-2025-6770: OS Command Injection in Ivanti EPMM <12.5.0.2
CVE-2025-6770 - July 08, 2025

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution

Shell injection

RCE in API of Ivanti Endpoint Manager Mobile <=12.5 via Authenticated API Calls
CVE-2025-4428 7.2 - High - May 13, 2025

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

Code Injection

API Auth Bypass in Ivanti Endpoint Manager Mobile <12.5.0.0
CVE-2025-4427 5.3 - Medium - May 13, 2025

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

Authentication Bypass Using an Alternate Path or Channel

Ivanti EPMM Local Auth Insecure Permissions <12.1.0.4
CVE-2024-7612 7.8 - High - October 08, 2024

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

Incorrect Permission Assignment for Critical Resource

Improper Auth in EPMM Web Component <12.1.0.1
CVE-2024-34788 6.5 - Medium - August 07, 2024

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

authentification

Unauth Exec via EPMM Web Component <12.1.0.1
CVE-2024-36130 9.8 - Critical - August 07, 2024

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.

authentification

EPMM Web component insecure deserialization (pre-12.1.0.1) OS cmd exec
CVE-2024-36131 8.8 - High - August 07, 2024

An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.

Marshaling, Unmarshaling

EPMM <12.1.0.1 Auth Bypass via Insufficient Auth Control (CVE-2024-36132)
CVE-2024-36132 7.5 - High - August 07, 2024

Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.

authentification

SQL Injection in EPMM Web Component (before v12.1.0.0)
CVE-2023-46807 - May 22, 2024

An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.

Unprivileged SQLi in EPMM <12.1.0.0 Web Component
CVE-2023-46806 - May 22, 2024

An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.

Local Privilege Escalation in EPMM <12.1.0.0 (Authenticated Shell Bypass)
CVE-2024-22026 6.7 - Medium - May 22, 2024

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

EPMM 11.10-11.8 Unauth Impersonation via Device Enrollment
CVE-2023-39335 9.8 - Critical - November 15, 2023

A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized access and potential misuse of user accounts and resources.

EPMM 11.811.10: Device ID Info Disclosure
CVE-2023-39337 9.1 - Critical - November 15, 2023

A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability poses a serious security risk, potentially exposing confidential data and system integrity.

Authentication Bypass in Ivanti EPMM < 11.10 (CVE-2023-35082)
CVE-2023-35082 - August 15, 2023

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

Path Traversal in Ivanti EPMM < 11.10.0.3/11.9.1.2/11.8.1.2 Admin File Write
CVE-2023-35081 - August 03, 2023

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

Directory traversal

Auth Bypass in Ivanti EPMM: Unauthorized Access
CVE-2023-35078 - July 25, 2023

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

authentification

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Ivanti Endpoint Manager Mobile or by Ivanti? Click the Watch button to subscribe.

 

Ivanti
Vendor

subscribe