SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-18851

HIGH · CVSS 8.8 EPSS 1.02%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

Ivanti Endpoint Manager Mobile versions prior to 12.10.0.0, 12.9.0.2, and 12.8.0.4 are vulnerable due to a missing authorization flaw that allows remote authenticated attackers to escalate their privileges to administrative levels. This high-severity vulnerability poses significant risks to organizations using these versions, as it could lead to unauthorized access and control over sensitive mobile management functions. Organizations utilizing affected Ivanti products should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-18851
Severity
HIGH
CVSS
8.8
EPSS
1.02%
Ivanti

Original NVD Description

Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.

Related CVEs

Other vulnerabilities affecting the same vendor(s)