CVE-2026-18851: Ivanti Endpoint Manager Mobile
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
Affected products
- Ivanti Endpoint Manager Mobile: before 12.8.0.4 (fixed in 12.8.0.4); from 12.9.0.0, before 12.9.0.2 (fixed in 12.9.0.2); version 12.10.0.0 only
Published 2026-09-08. Last modified 2026-09-09.