# Ivanti EPMM (MobileIron Core) unauthenticated API access

Source: https://startwithidentity.com/cves/cve-2023-35078/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

Ivanti EPMM (formerly MobileIron Core), versions 11.8, 11.9, and 11.10, exposed authenticated API functionality to an unauthenticated caller. Attackers read user and device inventories and, chained with CVE-2023-35081, wrote to the appliance. CISA KEV. Disclosed 24 July 2023 after in-the-wild use.

## Why it matters

EPMM decides which phones are trusted for [Conditional Access](https://startwithidentity.com/glossary/conditional-access/) and which users get mail. An unauthenticated API there is an identity bypass that your [IdP](https://startwithidentity.com/glossary/identity-provider/) never sees. The 2025 [addUser](https://startwithidentity.com/cves/cve-2025-55129/) bug is the same product class failing again.

## What to do

- Patch EPMM. If it was internet-facing in July 2023, assume data was read and review device-compliance decisions made afterward.
- Take EPMM admin and API off the internet.
- Pair device trust with [phishing-resistant MFA](https://startwithidentity.com/glossary/phishing-resistant-mfa/). MDM compromise should not be enough to become the user.

## After you patch

Edge appliances sit outside the estate and hold credentials into it, which is why this class keeps producing multi-victim campaigns.

- **Revoke all sessions on the appliance**, then rotate the directory or [LDAP](https://startwithidentity.com/glossary/federation/) service account it uses for authentication.
- **Rotate certificates and any stored integration credentials**, since configuration stores on these devices are a routine post-exploitation target.
- **Hunt for authenticated sessions with no matching interactive login**, and for logins from ASNs that had never appeared before the disclosure date.
- **Check downstream**: anything the appliance could reach or authenticate to is in scope, including [SSO](https://startwithidentity.com/glossary/sso/)-connected applications.

## Sources

- [NVD: CVE-2023-35078](https://nvd.nist.gov/vuln/detail/CVE-2023-35078)
- Ivanti, CVE-2023-35078 blog, 24 July 2023
- CISA KEV
