Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3451 articles · 142163 vulns · 36/41 feeds (7d)
← Back to list
7.0
CVE-2026-5788PATCHED
ivanti · endpoint manager mobile

CVE-2026-5788: An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticat

Description

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

Affected Products

VendorProductVersions
ivantiendpoint manager mobile—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
ivantiendpoint manager mobilecert_advisory90%

References

  • https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs

Related News (3 articles)

Tier B
BSI Advisories3d ago
[NEU] [hoch] Ivanti Endpoint Manager Mobile: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
SecurityWeek3d ago
Ivanti Patches EPMM Zero-Day Exploited in Targeted Attacks
→ No new info (linked only)
Tier C
VulDB4d ago
CVE-2026-5788 | Ivanti Endpoint Manager Mobile 12.6.1.1/12.7.0.1/12.8.0.1 access control
→ No new info (linked only)
CVSS 3.17.0 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
CISA KEV❌ No
Actively exploited❌ No
Patch available
12.8.0.112.7.0.112.6.1.1
CWECWE-284
PublishedMay 7, 2026
Last enriched4d agov2
Trending Score28
Source articles3
Independent3
Info Completeness8/14
Missing: versions, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-6973EXPKEV
CVE-2026-6973: An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic
Trending: 141
HIGHCVE-2026-7821
CVE-2026-7821: Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen
Trending: 34
HIGHCVE-2026-5787
CVE-2026-5787: An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unaut
Trending: 31
HIGHCVE-2026-5786
CVE-2026-5786: An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote
Trending: 31
HIGHCVE-2026-4913EXP
CVE-2026-4913: Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker t
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 7, 2026
Discovered by ZDM
May 7, 2026
Updated: severity
May 7, 2026
Patch Available
May 7, 2026

Version History

v2
Last enriched 4d ago
v2Tier C4d ago

Updated severity to CRITICAL and corrected exploit availability to false.

severity
via VulDB
v14d ago

Initial creation