Y-Security discovered multiple vulnerabilities affecting the BlackBerry UEM software by BlackBerry. Affected versions include at least 12.22.1.
| Software | BlackBerry UEM | |
| Vendor | BlackBerry | |
| Version | UEM <=12.23.0 QF8 and <= UEM 12.22.1 QF7 | |
| CVE | CVE-2026-18084 | CVE-2026-18085 |
| Type of Issue | Cross-Site Scripting | Denial of Service, Reflected Download |
| CWE | CWE-79 | CWE-1236 |
| OWASP | WSTG-INPV-02 | WSTG-BUSL-08 |
Summary
BlackBerry UEM (Unified Endpoint Management) is a cloud-based or on-premises platform for the centralized management, security and control of mobile devices, laptops and endpoints across an organization. The application enables devices to be enrolled and configured efficiently, corporate data to be separated from personal data, and security policies to be enforced and monitored in a compliance-ready manner.
The Cross-Site Scripting (CVE-2026-18084) vulnerability allows an attacker to execute arbitrary JavaScript in a victim’s browser via crafted input in the affected parameters. The application fails to safely encode user-supplied input before it is interpreted by the client, allowing malicious scripts to be embedded and executed in the context of the victim’s session. This access can then be used to hijack user sessions, steal credentials or other sensitive data, or deliver further payloads to attack the victim’s client applications, such as browser plugins. Additionally, the injected code can be stored within the application and later retrieved and executed in the browser of other users, allowing the attack to persist beyond the initial request.
The Denial of Service, Reflected Download (CVE-2026-18085) vulnerability allows a remote attacker to distribute arbitrary content or cause a Denial-of-Service condition via crafted HTTP requests. The application processes user-supplied input, which is subsequently reflected in the server response and offered for download. This can be abused to distribute arbitrary file types such as .ps1 (Power Shell scripts) or .exe (executable) in order to facilitate further attacks against user systems. Additionally a Denial-of-Service condition may be caused by requesting or generating excessively large amounts of data using specially crafted HTTP requests.
Mitigation & Recommendation
BlackBerry PSIRT (Product Security Incident Response Team) confirmed that the vulnerabilities have been successfully remediated in the latest release BlackBerry UEM 12.23.0 QF10 and BlackBerry UEM 12.22.1 QF8. As of now, the implemented security measurements have not been verified by Y-Security. Further information can also be found in BSRT-2026-001 Vulnerabilities in BlackBerry UEM Management Console Impact BlackBerry UEM.
Disclosure Policy
At Y-Security we take security vulnerabilities seriously and follow a responsible disclosure policy. The responsible disclosure process was aligned to BlackBerry’s Coordinated Vulnerability Disclosure Policy.
Disclosure Timeline
| DATE | COMMENT |
|---|---|
| 13.05.2026 | Y-Security discovered security vulnerability |
| 13.05.2026 | Vulnerability communicated with Client |
| 20.05.2026 | Initial contact with BlackBerry Security Response Center |
| 21.05.2026 | Y-Security provided further information |
| 05.06.2026 | BlackBerry PSIRT confirmed vulnerabilities |
| 24.06.2026 | CVEs assigned |
| 28.07.2026 | Security Fix released by BlackBerry |
| 28.07.2026 | Security Advisory released by BlackBerry |
| 28.07.2026 | Security Advisory released by Y-Security |
Author
Christian Becker
christian@y-security.de
Y-Security GmbH
28. July 2026
