CVE-2026-5788
Ivanti Endpoint Manager Mobile vulnerability analysis and mitigation

Overview

CVE-2026-5788 is an Improper Access Control vulnerability (CWE-284) in Ivanti Endpoint Manager Mobile (EPMM) that allows a remote unauthenticated attacker to invoke arbitrary methods on affected systems. It affects Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.0, and 12.8.0.0, with fixed versions being 12.6.1.1, 12.7.0.1, and 12.8.0.1. The vulnerability was published on May 7, 2026, and is part of a broader set of EPMM flaws disclosed in Ivanti's May 2026 security advisory. The CVSS v3.1 base score is reported as 9.8 (Critical) by NVD, though ENISA's EUVD and GitHub Advisory Database assign a score of 7.0 (High) with higher attack complexity (GitHub Advisory, Ivanti Advisory).

Technical details

The root cause is Improper Access Control (CWE-284), where Ivanti EPMM fails to properly restrict access to certain API methods or endpoints, allowing unauthenticated remote attackers to invoke arbitrary methods without any credentials. The attack vector is network-based and requires no user interaction or privileges, making it trivially exploitable from the internet against exposed EPMM instances. CVE-2026-5788 is closely associated with CVE-2026-6973, a related RCE vulnerability in EPMM that has been confirmed under active exploitation; together, these flaws can be chained to achieve pre-authentication remote code execution with administrative-level access (GitHub Advisory, BleepingComputer).

Impact

Successful exploitation enables an unauthenticated remote attacker to invoke arbitrary methods on the EPMM server, which can lead to full system compromise including remote code execution, unauthorized read/write access to all managed device data, and service disruption. Because EPMM is a mobile device management platform, a compromised instance could expose sensitive enterprise data, managed device configurations, credentials, and enable lateral movement into the broader corporate network. The availability, integrity, and confidentiality of all data managed by the EPMM platform are at risk (GitHub Advisory, BleepingComputer).

Exploitability

CVE-2026-5788 has been exploited in the wild as a zero-day, with Ivanti confirming targeted attacks at the time of disclosure on May 7, 2026. The vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, with a KEV deadline that expired around May 10, 2026 (CTI Pilot). Approximately 850 internet-exposed EPMM servers were identified as potentially vulnerable at the time of disclosure (Logicity). The EPSS score is approximately 0.25%, though the real-world exploitation context elevates urgency significantly. No public proof-of-concept exploit code has been confirmed, but the vulnerability is being exploited in targeted attacks, reportedly leveraging credentials stolen in earlier January 2026 attacks (Dark Web Informer, BleepingComputer).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Ivanti EPMM instances using tools like Shodan or Censys, targeting versions prior to 12.6.1.1, 12.7.0.1, or 12.8.0.1. Approximately 850 such servers were publicly exposed at the time of disclosure.
  2. Identify vulnerable endpoint: Probe the EPMM administrative interface for API endpoints that lack proper authentication enforcement due to the improper access control flaw.
  3. Invoke arbitrary methods: Send crafted unauthenticated HTTP requests to the vulnerable API endpoint to invoke arbitrary server-side methods without supplying valid credentials.
  4. Chain with CVE-2026-6973: Use the access gained via CVE-2026-5788 to chain exploitation with CVE-2026-6973, which allows authenticated RCE, thereby achieving full remote code execution with administrative-level access on the EPMM server.
  5. Post-exploitation: Leverage the compromised EPMM server to access managed device data, extract credentials, deploy malware to managed endpoints, or pivot laterally into the enterprise network (BleepingComputer, The Hacker News).

Indicators of compromise

  • Network: Unexpected or anomalous unauthenticated HTTP requests to EPMM API endpoints, particularly those that should require authentication; outbound connections from the EPMM server to unknown external IPs.
  • Logs: EPMM access logs showing unauthenticated requests successfully invoking administrative or privileged API methods; authentication bypass patterns in web server logs; unusual API calls originating from unexpected source IPs.
  • File System: Unexpected new files, scripts, or web shells in the EPMM installation directory; unauthorized modifications to EPMM configuration files.
  • Process: Unusual child processes spawned by the EPMM service (e.g., shell interpreters, network utilities like curl, wget); unexpected outbound network connections initiated by the EPMM process.
  • Credential Activity: Evidence of previously stolen credentials (from January 2026 attacks) being used to authenticate to EPMM administrative interfaces (Dark Web Informer, BleepingComputer).

Mitigation and workarounds

Ivanti has released patched versions addressing CVE-2026-5788: 12.6.1.1, 12.7.0.1, and 12.8.0.1. Organizations should upgrade to one of these versions immediately, as the vulnerability is being actively exploited and the CISA KEV deadline has passed. As an interim measure where immediate patching is not possible, implement network-level controls to restrict access to EPMM administrative interfaces to trusted IP ranges only, and monitor for anomalous API activity. Refer to Ivanti's May 2026 Security Advisory for detailed patching instructions (Ivanti Advisory, GitHub Advisory).

Community reactions

Ivanti issued a security advisory on May 7, 2026, disclosing CVE-2026-5788 alongside four other EPMM vulnerabilities, confirming active exploitation in targeted attacks (Ivanti Advisory). BleepingComputer, The Hacker News, SecurityWeek, CyberScoop, and Heise all covered the disclosure prominently, highlighting the zero-day exploitation and the chaining with CVE-2026-6973 for RCE (BleepingComputer, SecurityWeek). Security researchers and the community noted that the exploitation reportedly leveraged credentials stolen in earlier January 2026 attacks, underscoring the persistent threat targeting Ivanti products (Dark Web Informer). CISA added the vulnerability to its KEV catalog, and national CERTs including Ireland's NCSC and Belgium's CCB issued advisories urging immediate patching.

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager Mobile vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-5788CRITICAL9.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-7821CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5787CRITICAL9.1
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-5786HIGH8.8
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
NoYesMay 07, 2026
CVE-2026-6973HIGH7.2
  • Ivanti Endpoint Manager Mobile logoIvanti Endpoint Manager Mobile
  • cpe:2.3:a:ivanti:endpoint_manager_mobile
YesYesMay 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management