CVE-2026-18085
MEDIUM
5.9
CVSS 4.0
Description
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
Metadata
Severity & Metrics
5.9
MEDIUM CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:L/SA:L
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| BlackBerry | UEM | — | 12.23.0 QF8 and earlier, 12.22.1 QF7 and earlier |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-74 | cna | CWE-74: Improper Neutralization of Special Elements in Output (Injection) |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.9 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:L/SA:L |
References (1)