← All Advisories

Ivanti EPMM authenticated remote OS command injection executes arbitrary commands as root

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-10727

Key Details

CVECVE-2026-10727
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-10727
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-10727