Ivanti Endpoint Manager Mobile Missing Authorization Leading to Administrator Privilege Escalation

Release Date: 15th September 2026 (Added 16 September 2026)

Impact : HIGH

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that operate Ivanti Endpoint Manager Mobile (EPMM) for mobile device management. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-18851 is a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM), a widely-deployed mobile device management (MDM) platform used by organizations and government agencies to manage and secure fleets of mobile devices. A missing-authorization flaw allows a remote attacker who already holds authenticated access to escalate their privileges to full administrator level on the EPMM platform. This advisory is issued alongside CERTVU Advisory 315 (Ivanti Neurons for ITSM), disclosed by Ivanti in the same September 2026 security update; EPMM is a distinct product from Neurons for ITSM with its own affected versions and its own fixed release, so it is covered separately here. Ivanti states it has no evidence of this vulnerability being exploited in the wild at the time of disclosure.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-18851
  2. https://www.ivanti.com/blog/september-2026-security-update