CVE-2026-8109

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.

medium 6.5 CVSS 3.1
Published: May 12, 2026
Modified: May 12, 2026
Vendor: Ivanti
Product: Endpoint Manager
Versions: 2024

Description

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.

References

Related CVEs