
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5788 is an Improper Access Control vulnerability (CWE-284) in Ivanti Endpoint Manager Mobile (EPMM) that allows a remote unauthenticated attacker to invoke arbitrary methods on affected systems. It affects Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.0, and 12.8.0.0, with fixed versions being 12.6.1.1, 12.7.0.1, and 12.8.0.1. The vulnerability was published on May 7, 2026, and is part of a broader set of EPMM flaws disclosed in Ivanti's May 2026 security advisory. The CVSS v3.1 base score is reported as 9.8 (Critical) by NVD, though ENISA's EUVD and GitHub Advisory Database assign a score of 7.0 (High) with higher attack complexity (GitHub Advisory, Ivanti Advisory).
The root cause is Improper Access Control (CWE-284), where Ivanti EPMM fails to properly restrict access to certain API methods or endpoints, allowing unauthenticated remote attackers to invoke arbitrary methods without any credentials. The attack vector is network-based and requires no user interaction or privileges, making it trivially exploitable from the internet against exposed EPMM instances. CVE-2026-5788 is closely associated with CVE-2026-6973, a related RCE vulnerability in EPMM that has been confirmed under active exploitation; together, these flaws can be chained to achieve pre-authentication remote code execution with administrative-level access (GitHub Advisory, BleepingComputer).
Successful exploitation enables an unauthenticated remote attacker to invoke arbitrary methods on the EPMM server, which can lead to full system compromise including remote code execution, unauthorized read/write access to all managed device data, and service disruption. Because EPMM is a mobile device management platform, a compromised instance could expose sensitive enterprise data, managed device configurations, credentials, and enable lateral movement into the broader corporate network. The availability, integrity, and confidentiality of all data managed by the EPMM platform are at risk (GitHub Advisory, BleepingComputer).
CVE-2026-5788 has been exploited in the wild as a zero-day, with Ivanti confirming targeted attacks at the time of disclosure on May 7, 2026. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, with a KEV deadline that expired around May 10, 2026 (CTI Pilot). Approximately 850 internet-exposed EPMM servers were identified as potentially vulnerable at the time of disclosure (Logicity). The EPSS score is approximately 0.25%, though the real-world exploitation context elevates urgency significantly. No public proof-of-concept exploit code has been confirmed, but the vulnerability is being exploited in targeted attacks, reportedly leveraging credentials stolen in earlier January 2026 attacks (Dark Web Informer, BleepingComputer).
curl, wget); unexpected outbound network connections initiated by the EPMM process.Ivanti has released patched versions addressing CVE-2026-5788: 12.6.1.1, 12.7.0.1, and 12.8.0.1. Organizations should upgrade to one of these versions immediately, as the vulnerability is being actively exploited and the CISA KEV deadline has passed. As an interim measure where immediate patching is not possible, implement network-level controls to restrict access to EPMM administrative interfaces to trusted IP ranges only, and monitor for anomalous API activity. Refer to Ivanti's May 2026 Security Advisory for detailed patching instructions (Ivanti Advisory, GitHub Advisory).
Ivanti issued a security advisory on May 7, 2026, disclosing CVE-2026-5788 alongside four other EPMM vulnerabilities, confirming active exploitation in targeted attacks (Ivanti Advisory). BleepingComputer, The Hacker News, SecurityWeek, CyberScoop, and Heise all covered the disclosure prominently, highlighting the zero-day exploitation and the chaining with CVE-2026-6973 for RCE (BleepingComputer, SecurityWeek). Security researchers and the community noted that the exploitation reportedly leveraged credentials stolen in earlier January 2026 attacks, underscoring the persistent threat targeting Ivanti products (Dark Web Informer). CISA added the vulnerability to its KEV catalog, and national CERTs including Ireland's NCSC and Belgium's CCB issued advisories urging immediate patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."