Executive brief
BlackBerry UEM is a management console used by organizations to secure and manage mobile devices and applications. A vulnerability in this console could allow an attacker to trick a user into downloading unauthorized files or cause a service disruption, potentially impacting the availability of the management system. This issue affects specific older versions of the software, and organizations should ensure they are running updated versions to maintain operational stability.
Technical details
An improper input validation vulnerability (CWE-74) exists in the BlackBerry UEM Management Console. The flaw allows for arbitrary file downloads and a potential Denial of Service (DoS) condition. The attack vector is network-based, though it requires high attack complexity and user interaction (UI:A) to succeed. The vulnerability affects BlackBerry UEM versions 12.23.0 QF8 and earlier, as well as 12.22.1 QF7 and earlier. Remediation typically involves upgrading to a patched version as specified in BlackBerry's security advisory.
Affected products
- BlackBerry UEM 12.23.0 QF8 and earlier, 12.22.1 QF7 and earlier
Timeline
- 2026-07-28: advisory