← Vulnerability feed

Vulnerability record · CVE-2024-36132 · published 7 August 2024

CVE-2024-36132: Ivanti endpoint manager mobile improper authentication vulnerability

Ivanti · Endpoint Manager Mobile

Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.

7.5 CVSS 3.1 High EPSS 1.2% · top 31.6% CWE-287 · Improper authentication
7.5CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-36132 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-1281Ivanti Endpoint Manager Mobile unauthenticated code injection RCEIvanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that permits unauthenticated remote code execution. With a CVSS 3.1 bas…KEVEPSS 99%analysed9.8CVE-2026-1340Ivanti Endpoint Manager Mobile code injection enables unauthenticated RCEIvanti Endpoint Manager Mobile (EPMM) contains a code injection flaw (CWE-94) that allows attackers to achieve unauthenticated remote code execution.…KEVEPSS 99%analysed9.8CVE-2023-35082Ivanti EPMM authentication bypass via unauthenticated API accessIvanti Endpoint Manager Mobile (EPMM) 11.10 and older contains an authentication bypass that lets unauthenticated users reach restricted functionalit…KEVEPSS 100%analysed9.8CVE-2023-35078Ivanti EPMM authentication bypass via unauthenticated API accessIvanti Endpoint Manager Mobile (EPMM) contains an improper authentication flaw (CWE-287) that lets unauthenticated users reach restricted functionali…KEVEPSS 100%analysed8.8CVE-2025-4428Ivanti Endpoint Manager Mobile API code injection enables remote code executionIvanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior contains a code injection flaw in its API component that lets an authenticated attacker exec…KEVEPSS 87%analysed7.5CVE-2025-4427Ivanti Endpoint Manager Mobile API authentication bypassIvanti Endpoint Manager Mobile 12.5.0.0 and earlier contains an authentication bypass in its API component, allowing access to protected resources wi…KEVEPSS 100%analysed7.2CVE-2026-6973Ivanti EPMM improper input validation enables remote code executionIvanti Endpoint Manager Mobile (EPMM) before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 contains an improper input validation flaw (CWE-20) that lets …KEVEPSS 2.5%analysed7.2CVE-2023-35081Ivanti EPMM path traversal allows authenticated admin arbitrary file writeIvanti Endpoint Manager Mobile (EPMM) contains a path traversal flaw (CWE-22) in versions 11.10.x before 11.10.0.3, 11.9.x before 11.9.1.2, and 11.8.…KEVEPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2024-36132), CISA KEV, FIRST EPSS (scores of 2026-10-08). This page is refreshed as NVD updates the record.