CVE-2023-35082: Ivanti EPMM / MobileIron Core authentication bypass, actively exploited
The short version: CVE-2023-35082 is an authentication bypass in Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core) that lets an unauthenticated attacker reach restricted API functionality. It arises from the same permissive request-filtering as CVE-2023-35078, but affects a wider range including older MobileIron Core releases. It scores a perfect 10.0, it's exploited in the wild, and it's in CISA's KEV catalog with known ransomware-campaign use. If you run an internet-facing EPMM or legacy MobileIron Core, patch and verify. Steady hands — but move.
At a glance
| Fact | Detail |
|---|---|
| Our severity take | High — unauthenticated access to a mobile-device-management server |
| CVSS v3.0 (NVD) | 10.0 — Critical · AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | ~99.99% · 99.99th percentile (2026-07-17) |
| In CISA KEV? | Yes — remediation was due 2024-02-08 |
| Known exploited? | Yes — exploited in the wild; KEV notes known ransomware-campaign use |
| Vulnerability type | Authentication bypass → unauthenticated access to restricted API functionality |
| Requires authenticated session? | No — pre-authentication |
| Affected | Ivanti EPMM 11.10 and earlier, including MobileIron Core 11.2 and older |
| Fixed in | 11.8.1.1 · 11.9.1.1 · 11.10.0.2 (and later) |
What you need to know
CVE-2023-35082 comes from the same root cause as CVE-2023-35078: certain entries in the EPMM web application's security filter chain are too permissive, so requests reach protected endpoints without authentication. What makes it a distinct CVE is reach — it extends the exposure back into older MobileIron Core releases that the first fix didn't fully cover.
Why it belongs at the top of the queue:
- It's pre-authentication and network-reachable. No credentials, no chain required.
- It hits legacy installs. Older MobileIron Core deployments — the kind most likely to be under-maintained — are in scope.
- It's confirmed exploited. CISA added it to KEV and flags known ransomware-campaign use.
How serious we see it
High — the 10.0 is not hyperbole here.
Unauthenticated access to a mobile-device-management server, confirmed exploited in the wild, is top-of-queue — and the extra concern with this one is that it reaches the older MobileIron Core installs that tend to be neglected. The bounded, reassuring part is that it's narrow and fixable: specific builds, published fixes, quick to determine exposure. Because it was exploited before patching, treat an exposed, unpatched server as potentially compromised.
Recommendations
Straight from Ivanti's advisory and CISA:
- Patch now. Upgrade to 11.8.1.1 / 11.9.1.1 / 11.10.0.2 or later; migrate legacy MobileIron Core onto a supported build.
- Hunt for compromise. Review access logs for unauthenticated hits on protected API paths.
- If compromised, respond fully. Rotate credentials, keys, and tokens, and investigate for data access and lateral movement.
- Harden exposure. Restrict who can reach the interface; keep administrative access off the public internet.
- Confirm your exposure first. Verify whether you run an internet-facing EPMM or MobileIron Core and which version.
How BreachRisk sees it
BreachRisk works from the outside in. From little more than your domain it discovers internet-facing Ivanti EPMM / MobileIron Core interfaces, fingerprints the product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one — surfaced at the top of your results because it's in KEV.
Legacy management servers are exactly where a continuous, attacker's-eye view earns its keep: the old MobileIron Core box still on the internet is the one attackers scan for, and BreachRisk keeps it on your radar first.