← Browse

CVE-2026-18085

Low

No strong exploitation signal.

CVSS base
6.9 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:H
EPSS — probability of exploitation (30 days)
0.2%
5.3th percentile
CISA KEV
Not listed
Weakness / dates
CWE-74
Published 2026-07-28 · modified 2026-08-14

CVSS breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:H

Attack VectorNNetwork
Attack ComplexityHHigh
Privileges RequiredNNone
User InteractionRRequired
ScopeCChanged
ConfidentialityNNone
IntegrityLLow
AvailabilityHHigh

Timeline

Description

An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.

Affected

blackberry

References

Official: NVD · CVE.org