An Improper Certificate Validation in Ivanti EPMM before...
High severity
Unreviewed
Published
May 7, 2026
to the GitHub Advisory Database
•
Updated May 7, 2026
Description
Published by the National Vulnerability Database
May 7, 2026
Published to the GitHub Advisory Database
May 7, 2026
Last updated
May 7, 2026
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
References