← Vulnerability feed

Vulnerability record · CVE-2023-35081 · published 3 August 2023

CVE-2023-35081: Ivanti EPMM path traversal allows authenticated admin arbitrary file write

Ivanti · Endpoint Manager Mobile

Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal flaw (CWE-22) in versions 11.10.x before 11.10.0.3, 11.9.x before 11.9.1.2, and 11.8.x before 11.8.1.2. An authenticated administrator can write arbitrary files onto the appliance. Because the affected product is a mobile device management server, file write access to the appliance is a serious foothold concern.

7.2 CVSS 3.1 High CISA KEV since 31 Jul 2023 EPSS 64% · top 0.8% CWE-22 · Path traversal
7.2CVSS 3.1 base score
64%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is in CISA KEV with very high EPSS, but exploitation requires an authenticated administrator account, which limits who can trigger it.

What it is

Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal flaw (CWE-22) in versions 11.10.x before 11.10.0.3, 11.9.x before 11.9.1.2, and 11.8.x before 11.8.1.2. An authenticated administrator can write arbitrary files onto the appliance. Because the affected product is a mobile device management server, file write access to the appliance is a serious foothold concern.

Impact

An attacker with administrator access gains the ability to write arbitrary files on the EPMM appliance, which can lead to code execution or full compromise of the management server. That server typically holds control over managed mobile devices and related credentials.

Attack surface

Reachable over the network (CVSS vector AV:N) with low attack complexity, but it requires high privileges (PR:H), meaning a valid administrator account on EPMM. No user interaction is needed (UI:N).

Exploitation

It is listed in CISA's Known Exploited Vulnerabilities catalog with a 2023-07-31 addition date, and EPSS gives a 30-day probability of 0.63577 (99.2nd percentile), indicating active exploitation is expected. No ransomware campaign use is documented in the record.

What to do

  • Upgrade EPMM to 11.10.0.3, 11.9.1.2, or 11.8.1.2 (or later) as directed by the vendor advisory.
  • If patching is not immediately possible, apply the vendor's documented mitigations or discontinue use of the product per CISA's required action.
  • Restrict and audit administrator accounts on EPMM; remove unused or shared admin credentials.
  • Limit network exposure of the EPMM administrative interface to trusted management networks.
  • Monitor for unexpected file changes on the EPMM appliance after patching.

Detection

  • Review EPMM appliance file system and logs for unexpected or newly written files, especially outside expected directories.
  • Alert on administrator logins or admin-level actions from unusual source IPs or at unusual times.
  • Correlate EPMM admin activity with outbound connections or subsequent process execution on the appliance.
  • Track EPMM versions in inventory and flag any host still below the fixed builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-35081 to the Known Exploited Vulnerabilities catalog on 31 July 2023 as "Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 August 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-35081 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-1281Ivanti Endpoint Manager Mobile unauthenticated code injection RCEIvanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that permits unauthenticated remote code execution. With a CVSS 3.1 bas…KEVEPSS 99%analysed9.8CVE-2026-1340Ivanti Endpoint Manager Mobile code injection enables unauthenticated RCEIvanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that allows attackers to achieve unauthenticated remote code execution.…KEVEPSS 99%analysed9.8CVE-2023-35082Ivanti EPMM authentication bypass via unauthenticated API accessIvanti Endpoint Manager Mobile (EPMM) 11.10 and older contains an authentication bypass that lets unauthenticated users reach restricted functionalit…KEVEPSS 100%analysed9.8CVE-2023-35078Ivanti EPMM authentication bypass via unauthenticated API accessIvanti Endpoint Manager Mobile (EPMM) contains an improper authentication flaw (CWE-287) that lets unauthenticated users reach restricted functionali…KEVEPSS 100%analysed8.8CVE-2025-4428Ivanti Endpoint Manager Mobile API code injection enables remote code executionIvanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior contains a code injection flaw in its API component that lets an authenticated attacker exec…KEVEPSS 87%analysed7.5CVE-2025-4427Ivanti Endpoint Manager Mobile API authentication bypassIvanti Endpoint Manager Mobile 12.5.0.0 and earlier contains an authentication bypass in its API component, allowing access to protected resources wi…KEVEPSS 100%analysed7.2CVE-2026-6973Ivanti EPMM improper input validation enables remote code executionIvanti Endpoint Manager Mobile (EPMM) before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 contains an improper input validation flaw (CWE-20) that lets …KEVEPSS 2.5%analysed9.8CVE-2026-5788Ivanti endpoint manager mobile improper access control vulnerabilityAn Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitra…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2023-35081), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.