CVE-2023-35078
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
- Published
- Jul 25, 2023
- Updated
- Aug 5, 2026
- Assigning CNA
- hackerone
- Evidence observed
- Jul 25, 2023
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
Sources
7- CVE-2023-35078Exploit
CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool
Ivanti Endpoint Manager Mobile (EPMM) POC
Shell script to check Ivanti EPMM (MobileIron Core) instances for CVE-2023-35078 remote unauthenticated API access vulnerability, with Shodan dorks for target discovery.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.