CVE-2023-35082: Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-01-18. EPSS: 100% chance of exploitation in the next 30 days.
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.
Affected products
- Ivanti Endpoint Manager Mobile: before 11.11.0 (fixed in 11.11.0)
Published 2023-08-15. Last modified 2026-06-17.