Executive brief
Ivanti Sentry, a gateway used to manage and secure traffic between mobile devices and corporate servers, contains a critical security flaw. An attacker can exploit this vulnerability over the internet without needing any login credentials to take full control of the system. This could lead to a complete compromise of the appliance, allowing unauthorized access to sensitive corporate data or serving as a foothold for further attacks on the internal network.
Technical details
An OS command injection vulnerability (CWE-78) exists in Ivanti Sentry (formerly MobileIron Sentry) due to improper neutralization of special elements in user-supplied input. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to an exposed Sentry interface, leading to remote code execution with root privileges. The vulnerability is particularly impactful when the appliance is in an unmanaged state with externally reachable endpoints. Exploitation is mitigated if mTLS is used with EPMM or if HTTPS access is restricted through Neurons for MDM. Ivanti has released patches in versions R10.5.2, R10.6.2, and R10.7.1.
Affected products
- Ivanti Sentry (formerly MobileIron Sentry) Before R10.5.2, R10.6.2, and R10.7.1
Timeline
- 2026-06-09: advisory: Initial advisory published by Ivanti
- 2026-06-11: disclosed: CVE record published to NVD
- 2026-06-11: exploited: Reported as being exploited in the wild