
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5786 is an Improper Access Control vulnerability (CWE-284) in Ivanti Endpoint Manager Mobile (EPMM) that allows a remote authenticated attacker to escalate privileges and gain full administrative access to the affected system. It affects Ivanti EPMM versions prior to 12.6.1.1, version 12.7.0.0 (fixed in 12.7.0.1), and version 12.8.0.0 (fixed in 12.8.0.1). The vulnerability was published on May 7, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Ivanti Advisory).
The vulnerability is rooted in improper access control (CWE-284), where Ivanti EPMM fails to correctly restrict or enforce authorization boundaries for certain operations accessible to authenticated users. An attacker with low-level authenticated access can exploit this flaw over the network without user interaction or elevated complexity, effectively bypassing privilege checks to obtain administrative control. The attack vector is network-based, requires only low privileges, and no user interaction, making it straightforward to exploit once an attacker has any valid credentials. This vulnerability is part of a broader set of EPMM flaws disclosed in May 2026, and has been noted in conjunction with CVE-2026-6973 (an RCE vulnerability), where credentials stolen in earlier attacks were reportedly used to chain exploitation (GitHub Advisory, Ivanti Advisory).
Successful exploitation allows an authenticated attacker to gain full administrative access to the Ivanti EPMM platform, resulting in high impact to confidentiality, integrity, and availability. An attacker with administrative control over EPMM can manage enrolled mobile devices, access sensitive device and user data, push malicious configurations or applications, and potentially pivot to managed endpoints across the organization. The scope of impact extends beyond the EPMM server itself to all devices under its management (GitHub Advisory, Feedly).
CVE-2026-5786 has been observed exploited in the wild as part of zero-day attacks, reportedly in conjunction with CVE-2026-6973 (an RCE vulnerability), where attackers leveraged credentials stolen in prior January 2026 attacks to chain exploitation (BleepingComputer, Dark Web Informer). The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, with a KEV deadline that expired around May 10, 2026 (CTI Pilot). Approximately 850 internet-exposed EPMM servers were identified as potentially vulnerable at the time of disclosure (Logicity). The EPSS score is approximately 0.395–0.455%, though real-world exploitation has already been confirmed. No public proof-of-concept exploit code has been identified as of the time of reporting (Feedly).
Ivanti has released patched versions addressing CVE-2026-5786: update to EPMM 12.6.1.1, 12.7.0.1, or 12.8.0.1 or later immediately. As a network-level workaround, restrict access to the EPMM management interface to trusted IP ranges only, preventing unauthorized network access. Organizations should also audit all EPMM administrator accounts for unauthorized additions or privilege changes, and review access logs for signs of exploitation. Given CISA KEV listing and confirmed in-the-wild exploitation, patching should be treated as urgent (Ivanti Advisory, GitHub Advisory).
Ivanti issued a security advisory on May 7, 2026, disclosing CVE-2026-5786 alongside four other EPMM vulnerabilities, noting that at least one (CVE-2026-6973) was under active exploitation (BleepingComputer, SecurityWeek). Security researchers and media outlets including The Hacker News, BleepingComputer, Help Net Security, and SecurityWeek covered the disclosure extensively, highlighting the chaining of CVE-2026-5786 with CVE-2026-6973 for pre-auth RCE and the use of previously stolen credentials in attacks (The Hacker News, Help Net Security). Kudelski Security published analysis noting that CVE-2026-6973 allows RCE with admin credentials, underscoring the severity of privilege escalation via CVE-2026-5786 as a prerequisite (Kudelski Security). The Belgian CCB and Ireland's NCSC also issued warnings urging immediate patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."