Junglewise Threat Intelligence

CVE-2026-18085: BlackBerry UEM improper input validation in Management Console

CVE-2026-18085 · Severity: info · CVSS 5.9 · Published 2026-07-28

Vendors: Blackberry.

Executive brief

BlackBerry UEM is a management console used by organizations to secure and manage mobile devices and applications. A vulnerability in this console could allow an attacker to trick a user into downloading unauthorized files or cause a service disruption, potentially impacting the availability of the management system. This issue affects specific older versions of the software, and organizations should ensure they are running updated versions to maintain operational stability.

Technical details

An improper input validation vulnerability (CWE-74) exists in the BlackBerry UEM Management Console. The flaw allows for arbitrary file downloads and a potential Denial of Service (DoS) condition. The attack vector is network-based, though it requires high attack complexity and user interaction (UI:A) to succeed. The vulnerability affects BlackBerry UEM versions 12.23.0 QF8 and earlier, as well as 12.22.1 QF7 and earlier. Remediation typically involves upgrading to a patched version as specified in BlackBerry's security advisory.

Affected products

  • BlackBerry UEM 12.23.0 QF8 and earlier, 12.22.1 QF7 and earlier

Timeline

  • 2026-07-28: advisory

References