Critical severity9.8CISA KEVNVD Advisory· Published Aug 15, 2023· Updated Jun 17, 2026
CVE-2023-35082
CVE-2023-35082
Description
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.
Affected products
4- cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*Range: <11.11.0
- Range: <=11.2
Patches
Vulnerability mechanics
References
2News mentions
1- INC Ransomware Uses Rust-Based Windows and Linux/ESXi Encryptors in New AttacksCyber Security News · Jun 19, 2026