Configuration in Endpoint Manager Mobile (formerly MobileIron Core) - #VU134235

 

Configuration in Endpoint Manager Mobile (formerly MobileIron Core) - #VU134235

Published: June 10, 2026


Vulnerability identifier: #VU134235
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The issue may allow a remote user to bypass implemented security restrictions.

The issue exists due to a missing configuration control. A remote authenticated user can inject arbitrary Apache directives and execute arbitrary code on the system.


Affected software

Endpoint Manager Mobile (formerly MobileIron Core)

Remediation

Install updates from vendor's website.

Endpoint Manager Mobile (formerly MobileIron Core) - addressed in versions 12.7.0.2, 12.8.0.3, 12.9.0.1

External References

Related Security Bulletins