CVE-2026-18851: Ivanti Endpoint Manager Mobile

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.

Affected products

  • Ivanti Endpoint Manager Mobile: before 12.8.0.4 (fixed in 12.8.0.4); from 12.9.0.0, before 12.9.0.2 (fixed in 12.9.0.2); version 12.10.0.0 only

Published 2026-09-08. Last modified 2026-09-09.