Improper Authentication in Endpoint Manager Mobile (formerly MobileIron Core) - CVE-2023-35078
Published: July 25, 2023 / Updated: August 22, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an unspecified error in the authentication process. A remote attacker can bypass authentication and gain unauthorized access to the application.
Note, the vulnerability is being actively exploited in the wild as per Ivanti customers. The company at the moment did not comment on the incident and concealed all information about this vulnerability.
Affected software
How to mitigate CVE-2023-35078
Links to Public Exploits and PoC-codes
- Exploit #11877 - CVE-2023-35078 (CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool) (August 22, 2025)
- Exploit #9520 - CVE-2023-35078 (Tools to scanner & exploit cve-2023-35078) (January 23, 2024)
- Exploit #9227 - CVE-2023-35078 (Ivanti Endpoint Manager Mobile exploit) (August 4, 2023)
- Exploit #9219 - CVE-2023-35078-Poc-Exploit (This tool is built in golang language to exploit CVE-2023-35078 vulnerability inspired by similar tool in python language https://github.com/vchan-in/CVE-2023-35078-Exploit-POC) (August 2, 2023)
- Exploit #9218 - CVE-2023-35078 (Tools to scanner & exploit cve-2023-35078) (August 2, 2023)
- Exploit #9215 - nmap-CVE-2023-35078-Exploit (Nmap script to exploit CVE-2023-35078 - Mobile Iron Core) (August 2, 2023)
- Exploit #9211 - CVE-2023-35078-Exploit-POC (CVE-2023-35078 Remote Unauthenticated API Access Vulnerability Exploit POC) (July 30, 2023)