Junglewise Threat Intelligence

CVE-2026-18851: Ivanti Endpoint Manager Mobile privilege escalation via missing authorization

CVE-2026-18851 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Ivanti Endpoint Manager Mobile. Vendors: Ivanti.

Executive brief

Ivanti Endpoint Manager Mobile is a mobile device management solution used by organizations to manage corporate mobile devices and enforce security policies. A missing authorization vulnerability allows authenticated users to escalate their privileges to admin level, potentially giving attackers full control over the device management system if they compromise a standard user account.

Technical details

The vulnerability is a missing authorization (authorization bypass) vulnerability in Ivanti Endpoint Manager Mobile that affects versions before 12.10.0.0, 12.9.0.2, and 12.8.0.4. A remote authenticated attacker can exploit this flaw to escalate privileges from a regular user account to administrative level. The vulnerability requires prior authentication to the system, but does not require additional user interaction or network-layer exploitation. An attacker who gains a legitimate user account can leverage this flaw to gain full administrative control over the endpoint management system. Patches are available in versions 12.10.0.0, 12.9.0.2, and 12.8.0.4 or later.

Affected products

  • Ivanti Endpoint Manager Mobile before 12.10.0.0, 12.9.0.2, and 12.8.0.4

Timeline

  • 2026-09-08: disclosed

References

Related threats