CVE-2026-5787
Ivanti Endpoint Manager Mobile vulnerability analysis and mitigation

Overview

CVE-2026-5787 is an Improper Certificate Validation vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. It affects Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1 (specifically versions before 12.6.1.1, 12.7.0.0, and 12.8.0.0). The vulnerability was published on May 7, 2026, and patches were released the same day. It carries a CVSS v3.1 base score of 9.1 (Critical) per NVD, and 8.9 (High) per ENISA/GitHub Advisory (GitHub Advisory, Ivanti Advisory).

Technical details

The root cause is classified as CWE-295 (Improper Certificate Validation), meaning Ivanti EPMM fails to properly validate certificates presented by hosts claiming to be registered Sentry instances. An unauthenticated remote attacker can exploit this flaw over the network by impersonating a legitimate Sentry host during the certificate enrollment process, causing EPMM to issue valid CA-signed client certificates to the attacker-controlled host. No user interaction or prior privileges are required, making this exploitable entirely remotely. The attack is associated with CAPEC-459 (Creating a Rogue Certification Authority Certificate) and CAPEC-475 (Signature Spoofing by Improper Validation) (GitHub Advisory, Ivanti Advisory).

Impact

Successful exploitation allows an attacker to obtain CA-signed client certificates that authenticate them as trusted Sentry infrastructure components within the enterprise mobile management environment. This enables the attacker to authenticate as trusted infrastructure, compromising both the confidentiality and integrity of the EPMM deployment — potentially enabling interception of managed device communications, lateral movement within the enterprise, and further attacks against mobile device management (MDM) infrastructure. Availability is not directly impacted, but the trust compromise can have cascading effects on enterprise security posture (GitHub Advisory, Feedly).

Exploitability

CVE-2026-5787 has been reported as exploited in the wild in conjunction with CVE-2026-6973 (an authenticated RCE vulnerability in EPMM), forming a pre-authentication chain that enables full compromise. Reports indicate that credentials stolen in January 2026 attacks were leveraged in zero-day exploitation of related EPMM flaws, and approximately 850 EPMM servers were identified as internet-exposed at the time of disclosure. The vulnerability was added to CISA's Known Exploited Vulnerabilities (KEV) catalog, with a KEV remediation deadline noted as May 10, 2026. The EPSS score is approximately 0.045–0.064%, and no standalone public proof-of-concept exploit has been confirmed for this specific CVE (BleepingComputer, DarkWebInformer, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Ivanti EPMM instances using tools like Shodan or Censys, targeting versions prior to 12.6.1.1, 12.7.0.1, or 12.8.0.1. Approximately 850 servers were publicly exposed at the time of disclosure.
  2. Identify Sentry host identifiers: Gather information about registered Sentry host identifiers associated with the target EPMM deployment, potentially through prior reconnaissance or credential theft (as seen in January 2026 attacks).
  3. Craft impersonation request: Send a crafted network request to the EPMM certificate enrollment endpoint, presenting a spoofed Sentry host identity. Due to the improper certificate validation flaw, EPMM does not adequately verify the legitimacy of the requesting host.
  4. Obtain CA-signed certificate: EPMM issues a valid CA-signed client certificate to the attacker-controlled host, treating it as a trusted Sentry component.
  5. Authenticate as trusted infrastructure: Use the obtained certificate to authenticate against EPMM or related infrastructure as a trusted Sentry host, enabling further lateral movement, data access, or chaining with CVE-2026-6973 for authenticated RCE (BleepingComputer, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected certificate enrollment requests to EPMM from IP addresses not associated with known Sentry hosts; outbound connections from EPMM to unrecognized external hosts using newly issued client certificates.
  • Logs: EPMM audit logs showing certificate issuance events for Sentry host identifiers from unfamiliar source IPs or at unusual times; authentication events using client certificates issued to unrecognized hosts.
  • File System: Presence of newly issued CA-signed client certificates not corresponding to any registered Sentry appliance in the EPMM certificate store.
  • Process/Behavioral: Unexpected API calls or administrative actions originating from hosts presenting newly issued Sentry client certificates; signs of lateral movement from EPMM infrastructure to internal systems (BleepingComputer, Ivanti Advisory).

Mitigation and workarounds

Ivanti has released patched versions addressing CVE-2026-5787: upgrade to EPMM 12.6.1.1, 12.7.0.1, or 12.8.0.1 or later. If immediate patching is not possible, implement network segmentation to restrict access to EPMM systems and limit exposure of the certificate enrollment endpoint to trusted network segments only. Additionally, review and revoke any suspicious client certificates issued during the vulnerability window, and monitor for unauthorized certificate issuance. Given active exploitation and CISA KEV listing, patching should be treated as urgent (Ivanti Advisory, GitHub Advisory).

Community reactions

Ivanti issued a security advisory on May 7, 2026, disclosing CVE-2026-5787 alongside CVE-2026-6973 and other EPMM flaws, noting active exploitation in targeted attacks. BleepingComputer, The Hacker News, SecurityWeek, CyberScoop, and HelpNetSecurity all covered the disclosure, highlighting the zero-day exploitation and the chaining of CVE-2026-5787 with CVE-2026-6973 for pre-auth to RCE attack chains. Kudelski Security published technical analysis of the related RCE vulnerability. The Belgian Centre for Cybersecurity (CCB) and Ireland's NCSC issued warnings to their constituencies. Community trackers noted approximately 850 internet-exposed EPMM servers, amplifying urgency (BleepingComputer, SecurityWeek, CyberScoop).

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager Mobile vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5788CRITICAL9.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-7821CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5787CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5786HIGH8.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-6973HIGH7.2
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
YesYesMay 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management