Input validation error in Endpoint Manager Mobile (formerly MobileIron Core) - CVE-2026-6973

 

Input validation error in Endpoint Manager Mobile (formerly MobileIron Core) - CVE-2026-6973

Published: May 7, 2026


Vulnerability identifier: #VU130638
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-6973
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper input validation in Ivanti Endpoint Manager Mobile (EPMM) when processing input. A remote privileged user can send crafted input to execute arbitrary code.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Endpoint Manager Mobile (formerly MobileIron Core)

How to mitigate CVE-2026-6973

Install security update from vendor's website.

Endpoint Manager Mobile (formerly MobileIron Core) - addressed in versions 12.6.1.1, 12.7.0.1, 12.8.0.1

External References

Related Security Bulletins