BlackBerry UEM – CVE-2026-18084 & CVE-2026-18085

Y-Security discovered multiple vulnerabilities affecting the BlackBerry UEM software by BlackBerry. Affected versions include at least 12.22.1.

Software BlackBerry UEM
Vendor BlackBerry
Version UEM <=12.23.0 QF8 and <= UEM 12.22.1 QF7
CVE CVE-2026-18084 CVE-2026-18085
Type of Issue Cross-Site Scripting Denial of Service, Reflected Download
CWE CWE-79 CWE-1236
OWASP WSTG-INPV-02 WSTG-BUSL-08

Summary

BlackBerry UEM (Unified Endpoint Management) is a cloud-based or on-premises platform for the centralized management, security and control of mobile devices, laptops and endpoints across an organization. The application enables devices to be enrolled and configured efficiently, corporate data to be separated from personal data, and security policies to be enforced and monitored in a compliance-ready manner.

The Cross-Site Scripting (CVE-2026-18084) vulnerability allows an attacker to execute arbitrary JavaScript in a victim’s browser via crafted input in the affected parameters. The application fails to safely encode user-supplied input before it is interpreted by the client, allowing malicious scripts to be embedded and executed in the context of the victim’s session. This access can then be used to hijack user sessions, steal credentials or other sensitive data, or deliver further payloads to attack the victim’s client applications, such as browser plugins. Additionally, the injected code can be stored within the application and later retrieved and executed in the browser of other users, allowing the attack to persist beyond the initial request.

The Denial of Service, Reflected Download (CVE-2026-18085) vulnerability allows a remote attacker to distribute arbitrary content or cause a Denial-of-Service condition via crafted HTTP requests. The application processes user-supplied input, which is subsequently reflected in the server response and offered for download. This can be abused to distribute arbitrary file types such as .ps1 (Power Shell scripts) or .exe (executable) in order to facilitate further attacks against user systems. Additionally a Denial-of-Service condition may be caused by requesting or generating excessively large amounts of data using specially crafted HTTP requests.

Mitigation & Recommendation

BlackBerry PSIRT (Product Security Incident Response Team) confirmed that the vulnerabilities have been successfully remediated in the latest release BlackBerry UEM 12.23.0 QF10 and BlackBerry UEM 12.22.1 QF8. As of now, the implemented security measurements have not been verified by Y-Security. Further information can also be found in BSRT-2026-001 Vulnerabilities in BlackBerry UEM Management Console Impact BlackBerry UEM.

Disclosure Policy

At Y-Security we take security vulnerabilities seriously and follow a responsible disclosure policy. The responsible disclosure process was aligned to BlackBerry’s Coordinated Vulnerability Disclosure Policy.

Disclosure Timeline

DATE COMMENT
13.05.2026 Y-Security discovered security vulnerability
13.05.2026 Vulnerability communicated with Client
20.05.2026 Initial contact with BlackBerry Security Response Center
21.05.2026 Y-Security provided further information
05.06.2026 BlackBerry PSIRT confirmed vulnerabilities
24.06.2026 CVEs assigned
28.07.2026 Security Fix released by BlackBerry
28.07.2026 Security Advisory released by BlackBerry
28.07.2026 Security Advisory released by Y-Security

Author

Christian Becker
christian@y-security.de
Y-Security GmbH
28. July 2026