ivanti-epmm-exploit
SkillSecurityRuns an exploit that gains unauthorized remote control over vulnerable Ivanti mobile device management servers.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the ivanti-epmm-exploit skill
About this skill
🛡⚔️AI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reporting🛡⚔️
What this skill tells your AI
The instructions your AI receives, as published by shadd0wtaka/zen-ai-pentest in skills/module-ivanti-epmm-exploit/SKILL.md and read by ahel’s review.
CVE-2026-1281 & CVE-2026-1340: Ivanti EPMM RCE Exploit
Category: exploitation — Exploitation Module
Overview
CVE-2026-1281 & CVE-2026-1340: Ivanti EPMM RCE Exploit CVSS: 9.8 (Critical) Type: Pre-Authentication Remote Code Execution via Bash Arithmetic Expansion
This module exploits critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) allowing unauthenticated remote code execution through Bash arithmetic expansion abuse.
Technical Root Cause:
- Bash Arithmetic Expansion während Timestamp-Vergleich
- Betroffene Scripts: /mi/bin/map-appstore-url, /mi/bin/map-aft-store-url
- Vulnerable Endpo
Usage
Agent Integration
- Agent persona: auto-selected from category 'exploitation'
- MCP:
- API: with {"tool_name": "ivanti_epmm_exploit", "target": "example.com"}
Signals
- GitHub stars
- 469
- Forks
- 81
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
module-ivanti-epmm-exploit- Source
- github.com/shadd0wtaka/zen-ai-pentest