---
schema: 1
kind: vulnerability
title: "CVE-2026-6973 — Ivanti EPMM admin API improper input validation → RCE (CVSS 7.2, CISA KEV deadline 2026-05-10)"
headline: "CVE-2026-6973 — Ivanti EPMM admin API improper input validation → RCE (CVSS 7.2, CISA KEV deadline 2026-05-10)"
summary: "An authenticated administrative user can pass crafted input to an EPMM REST API endpoint, triggering OS-level code execution at the service account privilege level (CWE-20). Standalone, this requires admin credentials; chained after CVE-2026-5787 it is fully pre-auth."
discovered_at: "2026-05-08T05:00:08Z"
event_date: null
run_id: 2026-05-08-migrated
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - rce
  - cisa-kev
  - patch-available
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2026-6973
    cvss: "7.2"
    epss: null
    type: rce
    vector: zero-click
    auth: admin-required
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://nvd.nist.gov/vuln/detail/CVE-2026-6973"
    publisher: NVD — CVE-2026-6973
    role: primary
closed_sources: []
evidence:
  - quote: "An authenticated administrative user can pass crafted input to an EPMM REST API endpoint, triggering OS-level code execution at the service account privilege level (CWE-20)."
    publisher: ctipilot v2 brief (migrated)
verification: single-source
sourcing_note: "migration: evidence backfilled from v2 brief body (item predates the Evidence footer field)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-08.md
---

An authenticated administrative user can pass crafted input to an EPMM REST API endpoint, triggering OS-level code execution at the service account privilege level (CWE-20). Standalone, this requires admin credentials; chained after CVE-2026-5787 it is fully pre-auth. CISA KEV deadline: **2026-05-10**. EU internet-exposed on-prem instances: approx. 508 (Censys/Shodan). Fixed in 12.6.1.1, 12.7.0.1, 12.8.0.1.
