CVE-2026-1281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
29/01/2026
Last modified:
30/01/2026

Description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:* 12.5.0.0 (including)
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.7.0.0:*:*:*:*:*:*:*