CVE-2026-6973: Ivanti EPMM RCE — Admin-Level Access and MDM Infrastructure Compromise

Technical root cause and remediation for the unauthenticated administrative RCE flaw in Ivanti EPMM mobile device management systems.

CVE-2026-6973: Ivanti EPMM RCE — Admin-Level Access and MDM Infrastructure Compromise
📌
Security Roundup Series: Week of May 14, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-6973 Severity: CVSS 9.8 Status: ⚠️ Active Exploitation Confirmed Target Component: Ivanti Endpoint Manager Mobile (EPMM)

Ivanti disclosed CVE-2026-6973 in Endpoint Manager Mobile (EPMM) on May 7, 2026, with CISA simultaneously adding the flaw to its Known Exploited Vulnerabilities catalog and giving federal agencies until May 10 to patch. Ivanti confirmed active exploitation in a limited number of customer environments. The vulnerability allows remote code execution with administrative privileges — but requires an authenticated admin session, distinguishing it from the more easily exploitable flaws that preceded it.

Vulnerability Overview

CVE-2026-6973 is an improper input validation vulnerability in Ivanti EPMM (formerly MobileIron Core). Affected versions: EPMM 12.8.0.0 and all prior versions. Attackers with administrative credentials can submit a specially crafted request to an EPMM API endpoint, causing unsanitized input to be passed to an underlying OS command or system function, resulting in arbitrary code execution on the EPMM server.

CVSS v3.1: 7.2 (High) — AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

This is the third Ivanti EPMM RCE disclosed since January 2026. CVE-2026-1281 and CVE-2026-1340 (both critical, both previously KEV-listed) established the attack pattern: nation-state actors gain initial admin access through credential stuffing or lateral movement from compromised adjacent systems, then exploit EPMM RCE to pivot deeper into the enterprise MDM infrastructure — gaining the ability to push malicious MDM profiles to all enrolled mobile devices.

Attack Chain

Step 1: Obtain EPMM admin credentials
  - Credential stuffing against EPMM login portal (often internet-facing)
  - Lateral movement from compromised AD/LDAP source
  - Reuse of credentials from previous Ivanti breaches (CVE-2026-1281 victims)

Step 2: Authenticate to EPMM admin API
  POST /mifs/j_spring_security_check
  Content-Type: application/x-www-form-urlencoded
  j_username=admin&j_password=<stolen_creds>

Step 3: Trigger CVE-2026-6973 via malformed API call
  POST /api/v2/device/action/sendcommand
  Authorization: Bearer <admin_token>
  Content-Type: application/json
  {
    "commandType": "LOCK",
    "deviceIds": ["$(malicious_command)"]
  }
  # Unsanitized deviceIds value passed to underlying shell command

Step 4: Establish persistence on EPMM server
  # Reverse shell, cron job, or MDM profile push backdoor
  # Attacker can now push malicious profiles to ALL enrolled devices

Affected Versions

Vulnerable:  EPMM 12.8.0.0 and earlier
              EPMM 12.7.0.0 and earlier
              EPMM 12.6.1.0 and earlier

Fixed:       EPMM 12.8.0.1
             EPMM 12.7.0.1
             EPMM 12.6.1.1

Remediation

# 1. Update EPMM to fixed version
# Via Ivanti update portal — log in at: https://<your-epmm-host>/mifs/#/

# 2. Rotate ALL admin account credentials immediately
# Especially critical if you were affected by CVE-2026-1281 or CVE-2026-1340
# and did not already rotate credentials per Ivanti's January guidance

# 3. Review EPMM admin audit logs for suspicious API calls
# Log location: /mi/logs/audit.log (on-prem) or Ivanti Cloud console
grep -i "sendcommand\|deviceIds\|\$(" /mi/logs/audit.log | tail -500

# 4. Check for unexpected MDM profiles pushed to enrolled devices
# EPMM web UI: Policies & Configs -> Configurations -> Review recent changes

# 5. Restrict EPMM admin portal to known IPs via firewall rules
# EPMM should NEVER be directly internet-facing without IP restriction
iptables -A INPUT -p tcp --dport 443 -s <trusted_ip_range> -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j DROP

Detection

Indicators of exploitation:
  - Unusual API calls to /api/v2/device/action/sendcommand with non-standard deviceIds
  - Admin logins from unexpected geolocations or IP addresses
  - New MDM configuration profiles pushed outside change windows
  - Outbound connections from EPMM server to unknown external IPs

Splunk query:
  index=ivanti_epmm sourcetype=epmm:audit
  | search action="sendcommand" AND deviceIds="*$(*)*"
  | stats count by src_ip, admin_user, _time

→ Read the full weekly roundup: Security Roundup — Week of May 14, 2026


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther