Junglewise Threat Intelligence

CVE-2026-18084: BlackBerry UEM Management Console Cross-Site Scripting

CVE-2026-18084 · Severity: info · CVSS 8.6 · Published 2026-07-28

Vendors: Blackberry.

Executive brief

BlackBerry Unified Endpoint Management (UEM) is a platform used by organizations to manage and secure mobile devices and applications. A security vulnerability in its management console could allow an attacker to execute malicious scripts in the browser of an administrative user. If exploited, this could lead to unauthorized access to the management interface, potentially compromising the control and data of all managed mobile devices.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the BlackBerry UEM Management Console due to improper neutralization of input during web page generation (CWE-79). The vulnerability is network-reachable and requires user interaction, typically involving an administrative user visiting a malicious link or viewing attacker-controlled content. Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's session, potentially leading to full session hijacking or unauthorized administrative actions. The issue affects UEM versions 12.23.0 QF8 and earlier, as well as 12.22.1 QF7 and earlier.

Affected products

  • BlackBerry UEM Management Console 12.23.0 QF8 and earlier, 12.22.1 QF7 and earlier

Timeline

  • 2026-07-28: advisory
  • 2026-07-28: disclosed

References