Improper Certificate Validation in Endpoint Manager Mobile (formerly MobileIron Core) - CVE-2026-5787
Published: May 7, 2026
Endpoint Manager Mobile (formerly MobileIron Core)
Ivanti
Description
The vulnerability allows a remote attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
The vulnerability exists due to improper certificate validation in Ivanti Endpoint Manager Mobile (EPMM) when validating certificates. A remote attacker can present crafted certificate material to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.