Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-10986


Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.


Published

2025-10-14T15:16:01.780

Last Modified

2025-10-15T18:07:40.010

Status

Analyzed

Source

3c1d8aa1-5a33-4ea4-8992-aadd6440af75

Severity

CVSSv3.1: 4.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ivanti endpoint_manager_mobile < 12.4.0.4 Yes
Application ivanti endpoint_manager_mobile < 12.5.0.4 Yes
Application ivanti endpoint_manager_mobile < 12.6.0.2 Yes

References