Medium severity6.1NVD Advisory· Published Jul 28, 2026· Updated Aug 14, 2026
CVE-2026-18084
CVE-2026-18084
Description
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS).
This issue affects UEM: 12.23.0 QF8 or earlier.
Affected products
19cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:-:*:*:*:*:*:*+ 16 more
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:-:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:quick_fix1:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:quick_fix2:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:quick_fix3:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:quick_fix4:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:quick_fix5:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:quick_fix6:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:quick_fix7:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.23.0:quick_fix8:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.22.1:-:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.22.1:quick_fix1:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.22.1:quick_fix2:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.22.1:quick_fix3:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.22.1:quick_fix4:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.22.1:quick_fix5:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.22.1:quick_fix6:*:*:*:*:*:*
- cpe:2.3:a:blackberry:unified_endpoint_manager:12.22.1:quick_fix7:*:*:*:*:*:*
- Range: <=12.23.0 QF8
- Range: <=12.23.0 QF8
Patches
Vulnerability mechanics
References
1- support.blackberry.com/pkb/s/article/141208nvdVendor Advisory
News mentions
0No linked articles in our index yet.