Skip to main content

BlackBerry UEM Management Console – Cross-Site Scripting (CVE-2026-18084)

Scope: BlackBerry UEM Management Console, Versions Prior to QF9

Severity: High

A cross-site scripting (XSS) vulnerability exists in the BlackBerry UEM Management Console due to the application's failure to properly neutralize user-controllable input within the time zone parameter before rendering it in web page output. An unauthenticated remote attacker can exploit this flaw by injecting malicious JavaScript payloads. When an authenticated administrator accesses the affected page, the script executes within the context of their browser session. This can lead to the theft of administrative session tokens, complete takeover of the UEM console, unauthorized manipulation of mobile device policies, exfiltration of sensitive corporate data, and the deployment of malicious configurations to enrolled devices, potentially allowing the attacker to pivot into the broader corporate network. Organizations must apply the latest security patch (QF9 or later) provided by BlackBerry immediately. Administrators should also restrict access to the management console to trusted IP ranges, enforce multi-factor authentication (MFA) for all administrative accounts, and rigorously monitor console access logs for anomalous activity.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the NVD Record for CVE-2026-18084 and apply the necessary updates.