CVE-2026-6973: Ivanti EPMM RCE — Admin-Level Access and MDM Infrastructure Compromise
Technical root cause and remediation for the unauthenticated administrative RCE flaw in Ivanti EPMM mobile device management systems.
CVE-2026-6973
Severity: CVSS 9.8
Status: ⚠️ Active Exploitation Confirmed
Target Component: Ivanti Endpoint Manager Mobile (EPMM)
Ivanti disclosed CVE-2026-6973 in Endpoint Manager Mobile (EPMM) on May 7, 2026, with CISA simultaneously adding the flaw to its Known Exploited Vulnerabilities catalog and giving federal agencies until May 10 to patch. Ivanti confirmed active exploitation in a limited number of customer environments. The vulnerability allows remote code execution with administrative privileges — but requires an authenticated admin session, distinguishing it from the more easily exploitable flaws that preceded it.
Vulnerability Overview
CVE-2026-6973 is an improper input validation vulnerability in Ivanti EPMM (formerly MobileIron Core). Affected versions: EPMM 12.8.0.0 and all prior versions. Attackers with administrative credentials can submit a specially crafted request to an EPMM API endpoint, causing unsanitized input to be passed to an underlying OS command or system function, resulting in arbitrary code execution on the EPMM server.
CVSS v3.1: 7.2 (High) — AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
This is the third Ivanti EPMM RCE disclosed since January 2026. CVE-2026-1281 and CVE-2026-1340 (both critical, both previously KEV-listed) established the attack pattern: nation-state actors gain initial admin access through credential stuffing or lateral movement from compromised adjacent systems, then exploit EPMM RCE to pivot deeper into the enterprise MDM infrastructure — gaining the ability to push malicious MDM profiles to all enrolled mobile devices.
Attack Chain
Step 1: Obtain EPMM admin credentials
- Credential stuffing against EPMM login portal (often internet-facing)
- Lateral movement from compromised AD/LDAP source
- Reuse of credentials from previous Ivanti breaches (CVE-2026-1281 victims)
Step 2: Authenticate to EPMM admin API
POST /mifs/j_spring_security_check
Content-Type: application/x-www-form-urlencoded
j_username=admin&j_password=<stolen_creds>
Step 3: Trigger CVE-2026-6973 via malformed API call
POST /api/v2/device/action/sendcommand
Authorization: Bearer <admin_token>
Content-Type: application/json
{
"commandType": "LOCK",
"deviceIds": ["$(malicious_command)"]
}
# Unsanitized deviceIds value passed to underlying shell command
Step 4: Establish persistence on EPMM server
# Reverse shell, cron job, or MDM profile push backdoor
# Attacker can now push malicious profiles to ALL enrolled devicesAffected Versions
Vulnerable: EPMM 12.8.0.0 and earlier
EPMM 12.7.0.0 and earlier
EPMM 12.6.1.0 and earlier
Fixed: EPMM 12.8.0.1
EPMM 12.7.0.1
EPMM 12.6.1.1Remediation
# 1. Update EPMM to fixed version
# Via Ivanti update portal — log in at: https://<your-epmm-host>/mifs/#/
# 2. Rotate ALL admin account credentials immediately
# Especially critical if you were affected by CVE-2026-1281 or CVE-2026-1340
# and did not already rotate credentials per Ivanti's January guidance
# 3. Review EPMM admin audit logs for suspicious API calls
# Log location: /mi/logs/audit.log (on-prem) or Ivanti Cloud console
grep -i "sendcommand\|deviceIds\|\$(" /mi/logs/audit.log | tail -500
# 4. Check for unexpected MDM profiles pushed to enrolled devices
# EPMM web UI: Policies & Configs -> Configurations -> Review recent changes
# 5. Restrict EPMM admin portal to known IPs via firewall rules
# EPMM should NEVER be directly internet-facing without IP restriction
iptables -A INPUT -p tcp --dport 443 -s <trusted_ip_range> -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j DROPDetection
Indicators of exploitation:
- Unusual API calls to /api/v2/device/action/sendcommand with non-standard deviceIds
- Admin logins from unexpected geolocations or IP addresses
- New MDM configuration profiles pushed outside change windows
- Outbound connections from EPMM server to unknown external IPs
Splunk query:
index=ivanti_epmm sourcetype=epmm:audit
| search action="sendcommand" AND deviceIds="*$(*)*"
| stats count by src_ip, admin_user, _time→ Read the full weekly roundup: Security Roundup — Week of May 14, 2026