CVE-2026-18851 is a vulnerability in Ivanti Endpoint Manager Mobile
Published on September 8, 2026
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
Vulnerability Analysis
CVE-2026-18851 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-18851 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-18851
Want to know whenever a new CVE is published for Ivanti Endpoint Manager Mobile? stack.watch will email you.
Affected Versions
Ivanti Endpoint Manager Mobile:- Version 12.10.0.0 is unaffected.
- Version 12.9.0.2 is unaffected.
- Version 12.8.0.4 is unaffected.