Junglewise Threat Intelligence

CVE-2026-10727: Ivanti EPMM OS command injection in management interface

CVE-2026-10727 · Severity: high · CVSS 7.2 · Published 2026-06-09

Technologies: Ivanti Endpoint Manager Mobile (EPMM), Ivanti Endpoint Manager Mobile. Vendors: Ivanti.

Executive brief

Ivanti Endpoint Manager Mobile (EPMM) is a platform used by organizations to manage and secure mobile devices. A security vulnerability has been identified that could allow an administrative user to take full control of the underlying server. If exploited, an attacker could execute unauthorized commands with the highest level of system privileges, potentially leading to data theft or a complete service outage.

Technical details

An OS command injection vulnerability (CWE-78) exists in Ivanti Endpoint Manager Mobile (EPMM) versions prior to 12.9.0.1, 12.8.0.3, and 12.7.0.2. The flaw is rooted in the improper neutralization of special elements used in OS commands. A remote attacker with high-level administrative privileges can exploit this vulnerability via the network without user interaction. Successful exploitation allows the execution of arbitrary commands with root-level privileges on the underlying operating system. Ivanti has released patches to address this issue in the affected version branches.

Affected products

  • Ivanti Endpoint Manager Mobile (EPMM) Before 12.9.0.1, 12.8.0.3, and 12.7.0.2

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats