CVE-2026-18084

EUVD-2026-49898
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS).

This issue affects UEM: 12.23.0 QF8 or earlier.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.39%
Affected Products (NVD)
VendorProductVersion
blackberryunified_endpoint_manager
12.23.0
blackberryunified_endpoint_manager
12.23.0:quick_fix1
blackberryunified_endpoint_manager
12.23.0:quick_fix2
blackberryunified_endpoint_manager
12.23.0:quick_fix3
blackberryunified_endpoint_manager
12.23.0:quick_fix4
blackberryunified_endpoint_manager
12.23.0:quick_fix5
blackberryunified_endpoint_manager
12.23.0:quick_fix6
blackberryunified_endpoint_manager
12.23.0:quick_fix7
blackberryunified_endpoint_manager
12.23.0:quick_fix8
blackberryunified_endpoint_manager
12.22.1
blackberryunified_endpoint_manager
12.22.1:quick_fix1
blackberryunified_endpoint_manager
12.22.1:quick_fix2
blackberryunified_endpoint_manager
12.22.1:quick_fix3
blackberryunified_endpoint_manager
12.22.1:quick_fix4
blackberryunified_endpoint_manager
12.22.1:quick_fix5
blackberryunified_endpoint_manager
12.22.1:quick_fix6
blackberryunified_endpoint_manager
12.22.1:quick_fix7
𝑥
= Vulnerable software versions