---
schema: 1
kind: vulnerability
title: >
  CVE-2026-5787 — Ivanti EPMM improper certificate validation (pre-auth Sentry impersonation, CVSS
  9.1)
headline: >
  CVE-2026-5787 — Ivanti EPMM improper certificate validation (pre-auth Sentry impersonation, CVSS
  9.1)
summary: >
  EPMM's internal PKI issues CA-signed certificates to registered Sentry gateway hosts upon
  verified registration. CVE-2026-5787 (CWE-295) is a failure in that verification: an attacker
  submits a crafted registration request and EPMM issues a valid CA-signed certificate without
  confirming prior registration.
discovered_at: "2026-05-08T05:00:07Z"
updated_at: "2026-05-30T05:00:12Z"
event_date: null
run_id: 2026-05-08-migrated
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - pre-auth
  - auth-bypass
  - cisa-kev
  - patch-available
  - lpe
regions:
  - global
  - switzerland
sectors: []
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-5787
    cvss: "9.1"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
  - id: CVE-2026-8992
    cvss: "7.8"
    epss: null
    type: lpe
    vector: local
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://nvd.nist.gov/vuln/detail/CVE-2026-5787"
    publisher: NVD — CVE-2026-5787
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12548"
    publisher: NCSC Switzerland Security Hub
    role: primary
closed_sources: []
evidence:
  - quote: "EPMM's internal PKI issues CA-signed certificates to registered Sentry gateway hosts upon verified registration."
    publisher: ctipilot v2 brief (migrated)
verification: single-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions: []
updates:
  - at: "2026-05-30T05:00:12Z"
    run_id: 2026-05-30-aca445cc
    type: update
    summary: >
      UPDATE (originally covered 2026-05-08): NCSC Switzerland updated its Ivanti May 2026 advisory on
      29 May 2026, adding CVE-2026-8992, a local privilege escalation in the Ivanti Secure Access
      Client (NCSC Switzerland Security Hub, 2026-05-29). CVSS 3.1 = 7.8 HIGH.
    fields:
      - cves
      - regions
      - sources
      - tags
      - body
    merged_from: 2026-05-30/ivanti-secure-access-client-ncsc-ch-adds-cve-2026-8992-local
migrated_from: briefs/2026-05-08.md
---

EPMM's internal PKI issues CA-signed certificates to registered Sentry gateway hosts upon verified registration. CVE-2026-5787 (CWE-295) is a failure in that verification: an attacker submits a crafted registration request and EPMM issues a valid CA-signed certificate without confirming prior registration. The certificate carries Sentry-level trust and satisfies EPMM's administrative authentication gate, enabling the CVE-2026-6973 chain. No workaround fully mitigates CVE-2026-5787 in isolation; patching is required. Affected: all on-prem EPMM < 12.6.1.1 / 12.7.0.1 / 12.8.0.1.

## Update — 2026-05-30T05:00:12Z

NCSC Switzerland updated its Ivanti May 2026 advisory on 29 May 2026, adding CVE-2026-8992, a local privilege escalation in the Ivanti Secure Access Client ([NCSC Switzerland Security Hub, 2026-05-29](https://security-hub.ncsc.admin.ch/#/posts/12548)). CVSS 3.1 = 7.8 HIGH. A locally-authenticated attacker on a managed endpoint running the Ivanti SAC client can escalate from a standard Windows user session to local admin. Ivanti patched CVE-2026-8992 in all SAC client versions released on or after 12 May 2026. This is secondary to the actively-exploited CVE-2026-6973 (Ivanti EPMM admin-authenticated RCE, CISA KEV) which remains the highest-severity Ivanti item. Detection: Windows Event IDs 4672 and 4673 (special privilege assignment) correlated with Ivanti SAC process lineage (`ivanti-vpn.exe`, `Ivanti Secure Access Client.exe`). Hardening: update SAC client to any release from 12 May 2026 or later via EPMM-managed software inventory.
