BlackBerryCVE-2026-18085
BlackBerry UEM: improper input validation
Medium5.9CVE-2026-18085 · Published Jul 28, 2026 · updated Aug 14, 2026
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| UEM Product | <= 12.23.0 QF8 and earlier, 12.22.1 QF7 and earlier | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-74
More BlackBerry advisories
All BlackBerry| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | BlackBerry AtHoc IWS: cross-site scripting | Medium5.3 | 7.21 HF-734 |
| Jul 29 | BlackBerry QNX Software Development Platform: improper input validation | High7.0 | No fix yet |
| Jul 28 | BlackBerry UEM: cross-site scripting | High8.6 | No fix yet |
| Jul 14 | BlackBerry QNX: buffer overflow | High7.4 | No fix yet |
| Jul 14 | BlackBerry QNX: race condition | Medium6.4 | No fix yet |
| Jul 14 | BlackBerry QNX: attacker could cause a crash of the QNX Neutrino kernel | Medium6.2 | No fix yet |