CVE-2026-18085

EUVD-2026-49897
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.14%
Affected Products (NVD)
VendorProductVersion
blackberryunified_endpoint_manager
12.23.0
blackberryunified_endpoint_manager
12.23.0:quick_fix1
blackberryunified_endpoint_manager
12.23.0:quick_fix2
blackberryunified_endpoint_manager
12.23.0:quick_fix3
blackberryunified_endpoint_manager
12.23.0:quick_fix4
blackberryunified_endpoint_manager
12.23.0:quick_fix5
blackberryunified_endpoint_manager
12.23.0:quick_fix6
blackberryunified_endpoint_manager
12.23.0:quick_fix7
blackberryunified_endpoint_manager
12.23.0:quick_fix8
blackberryunified_endpoint_manager
12.22.1
blackberryunified_endpoint_manager
12.22.1:quick_fix1
blackberryunified_endpoint_manager
12.22.1:quick_fix2
blackberryunified_endpoint_manager
12.22.1:quick_fix3
blackberryunified_endpoint_manager
12.22.1:quick_fix4
blackberryunified_endpoint_manager
12.22.1:quick_fix5
blackberryunified_endpoint_manager
12.22.1:quick_fix6
blackberryunified_endpoint_manager
12.22.1:quick_fix7
𝑥
= Vulnerable software versions