endpoint_manager_mobile vulnerabilities
CVEs whose affected-version data names the endpoint_manager_mobile package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-18851High· 8.8Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
▾ Twilightivanti · endpoint_manager_mobileEPSS 1.0%via NVD
CVE-2023-35078Critical· 9.8CISA KEV0dayPoCAn authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
▾ Hadalivanti · endpoint_manager_mobileEPSS 100%via NVD