Configuration in Endpoint Manager Mobile (formerly MobileIron Core) - #VU134235
Published: June 10, 2026
Vulnerability identifier: #VU134235
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-16
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The issue may allow a remote user to bypass implemented security restrictions.
The issue exists due to a missing configuration control. A remote authenticated user can inject arbitrary Apache directives and execute arbitrary code on the system.
Affected software
Endpoint Manager Mobile (formerly MobileIron Core)
Remediation
Install updates from vendor's website.
Endpoint Manager Mobile (formerly MobileIron Core) - addressed in versions 12.7.0.2, 12.8.0.3, 12.9.0.1