CVE-2026-5786
Ivanti Endpoint Manager Mobile vulnerability analysis and mitigation

Overview

CVE-2026-5786 is an Improper Access Control vulnerability (CWE-284) in Ivanti Endpoint Manager Mobile (EPMM) that allows a remote authenticated attacker to escalate privileges and gain full administrative access to the affected system. It affects Ivanti EPMM versions prior to 12.6.1.1, version 12.7.0.0 (fixed in 12.7.0.1), and version 12.8.0.0 (fixed in 12.8.0.1). The vulnerability was published on May 7, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Ivanti Advisory).

Technical details

The vulnerability is rooted in improper access control (CWE-284), where Ivanti EPMM fails to correctly restrict or enforce authorization boundaries for certain operations accessible to authenticated users. An attacker with low-level authenticated access can exploit this flaw over the network without user interaction or elevated complexity, effectively bypassing privilege checks to obtain administrative control. The attack vector is network-based, requires only low privileges, and no user interaction, making it straightforward to exploit once an attacker has any valid credentials. This vulnerability is part of a broader set of EPMM flaws disclosed in May 2026, and has been noted in conjunction with CVE-2026-6973 (an RCE vulnerability), where credentials stolen in earlier attacks were reportedly used to chain exploitation (GitHub Advisory, Ivanti Advisory).

Impact

Successful exploitation allows an authenticated attacker to gain full administrative access to the Ivanti EPMM platform, resulting in high impact to confidentiality, integrity, and availability. An attacker with administrative control over EPMM can manage enrolled mobile devices, access sensitive device and user data, push malicious configurations or applications, and potentially pivot to managed endpoints across the organization. The scope of impact extends beyond the EPMM server itself to all devices under its management (GitHub Advisory, Feedly).

Exploitability

CVE-2026-5786 has been observed exploited in the wild as part of zero-day attacks, reportedly in conjunction with CVE-2026-6973 (an RCE vulnerability), where attackers leveraged credentials stolen in prior January 2026 attacks to chain exploitation (BleepingComputer, Dark Web Informer). The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, with a KEV deadline that expired around May 10, 2026 (CTI Pilot). Approximately 850 internet-exposed EPMM servers were identified as potentially vulnerable at the time of disclosure (Logicity). The EPSS score is approximately 0.395–0.455%, though real-world exploitation has already been confirmed. No public proof-of-concept exploit code has been identified as of the time of reporting (Feedly).

Exploitation steps

  1. Credential Acquisition: Obtain valid (low-privilege) credentials for the target Ivanti EPMM instance — attackers in observed campaigns reportedly reused credentials stolen in earlier (January 2026) attacks against Ivanti products.
  2. Reconnaissance: Identify internet-exposed Ivanti EPMM management interfaces using tools such as Shodan or Censys, filtering for versions prior to 12.6.1.1, 12.7.0.1, or 12.8.0.1.
  3. Authentication: Authenticate to the EPMM management interface using the acquired low-privilege credentials.
  4. Privilege Escalation via Access Control Bypass: Send crafted requests to EPMM API endpoints that fail to enforce proper authorization checks, exploiting the improper access control flaw (CWE-284) to escalate privileges to administrative level.
  5. Administrative Access: With administrative access obtained, perform actions such as managing enrolled devices, modifying configurations, deploying malicious profiles or applications, or chaining with CVE-2026-6973 for remote code execution on the EPMM server (BleepingComputer, Dark Web Informer).

Indicators of compromise

  • Logs: EPMM access logs showing authenticated low-privilege accounts performing administrative-level API calls or accessing admin-restricted endpoints; unexpected privilege changes recorded in audit logs.
  • Network: Unusual inbound requests to EPMM management interfaces from unexpected IP addresses or geographic locations; outbound connections from the EPMM server to unknown external hosts following authentication events.
  • Authentication: Login events using credentials associated with previously compromised accounts (particularly those active in January 2026 Ivanti-related incidents); multiple authentication attempts followed by immediate administrative actions.
  • Configuration Changes: Unexpected modifications to device management policies, enrollment profiles, or administrator account settings within the EPMM console.
  • Process/System: Anomalous processes spawned on the EPMM server, particularly if chained with CVE-2026-6973 RCE exploitation (BleepingComputer, Dark Web Informer).

Mitigation and workarounds

Ivanti has released patched versions addressing CVE-2026-5786: update to EPMM 12.6.1.1, 12.7.0.1, or 12.8.0.1 or later immediately. As a network-level workaround, restrict access to the EPMM management interface to trusted IP ranges only, preventing unauthorized network access. Organizations should also audit all EPMM administrator accounts for unauthorized additions or privilege changes, and review access logs for signs of exploitation. Given CISA KEV listing and confirmed in-the-wild exploitation, patching should be treated as urgent (Ivanti Advisory, GitHub Advisory).

Community reactions

Ivanti issued a security advisory on May 7, 2026, disclosing CVE-2026-5786 alongside four other EPMM vulnerabilities, noting that at least one (CVE-2026-6973) was under active exploitation (BleepingComputer, SecurityWeek). Security researchers and media outlets including The Hacker News, BleepingComputer, Help Net Security, and SecurityWeek covered the disclosure extensively, highlighting the chaining of CVE-2026-5786 with CVE-2026-6973 for pre-auth RCE and the use of previously stolen credentials in attacks (The Hacker News, Help Net Security). Kudelski Security published analysis noting that CVE-2026-6973 allows RCE with admin credentials, underscoring the severity of privilege escalation via CVE-2026-5786 as a prerequisite (Kudelski Security). The Belgian CCB and Ireland's NCSC also issued warnings urging immediate patching.

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager Mobile vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5788CRITICAL9.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-7821CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5787CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5786HIGH8.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-6973HIGH7.2
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
YesYesMay 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management