HIGH
CVE-2026-1603
CVSS
7.5
KEV
Description
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
Summary dbcve.org
Ivanti Endpoint Manager before version 2024 SU5 contains an authentication bypass vulnerability that allows remote unauthenticated attackers to access specific stored credential data. This is a pre-authentication flaw affecting the application's credential storage mechanism.
Mitigation
Upgrade Ivanti Endpoint Manager to version 2024 SU5 or later. If immediate upgrade is not feasible, restrict network access to the management interface and monitor for unauthorized access attempts.
Weakness (CWE)
CWE-288
CWE-306
Missing Authentication
EPSS Score
80.56%
Probability of exploitation in next 30 days
99.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.