HIGH

CVE-2026-1603

Ivanti Endpoint Manager 2026-02-10 CVSS v3.1
CVSS
7.5
KEV

Description

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

Summary dbcve.org

Ivanti Endpoint Manager before version 2024 SU5 contains an authentication bypass vulnerability that allows remote unauthenticated attackers to access specific stored credential data. This is a pre-authentication flaw affecting the application's credential storage mechanism.

Mitigation

Upgrade Ivanti Endpoint Manager to version 2024 SU5 or later. If immediate upgrade is not feasible, restrict network access to the management interface and monitor for unauthorized access attempts.

Weakness (CWE)

CWE-288
CWE-306 Missing Authentication

EPSS Score

80.56%
Probability of exploitation in next 30 days
99.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE