Skip to content
BlackBerryCVE-2026-18085

BlackBerry UEM: improper input validation

Medium5.9CVE-2026-18085 · Published Jul 28, 2026 · updated Aug 14, 2026

An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.

BlackBerry advisory

Affected versions

PackageAffectedFixed in
UEM
Product
<= 12.23.0 QF8 and earlier, 12.22.1 QF7 and earlierNo fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-74

More BlackBerry advisories

All BlackBerry
Advisory
BlackBerry AtHoc IWS: cross-site scripting
Medium5.3Aug 11
BlackBerry QNX Software Development Platform: improper input validation
High7.0Jul 29
BlackBerry UEM: cross-site scripting
High8.6Jul 28
BlackBerry QNX: buffer overflow
High7.4Jul 14
BlackBerry QNX: race condition
Medium6.4Jul 14
BlackBerry QNX: attacker could cause a crash of the QNX Neutrino kernel
Medium6.2Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.