← All Advisories

Ivanti EPMM Certificate Validation Flaw Allows an Unauthenticated Remote Attacker to Enroll Restricted Devices and Expose Appliance Information

Last refreshed2026-09-29

Status: UPDATED  |  Advisory ID: CVE-2026-7821

Key Details

CVECVE-2026-7821
CVSS Score / Version7.4 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsIvanti endpoint_manager_mobile
Classified asCWE-295 (Improper Certificate Validation)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Ivantiendpoint_manager_mobile
SubsystemsGeneral OT
SectorsMultiple

What to Know

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.

What to Do

Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-7821
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-7821
Vendor advisoryhttps://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs?language=en_US