CVE-2026-1603

9.5 CISA KEV

Ivanti · Endpoint Manager (EPM)

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

Executive summary

This critical authentication bypass vulnerability in Ivanti Endpoint Manager is actively exploited in the wild and enables unauthenticated attackers to exfiltrate sensitive credentials.

Vulnerability

The flaw is an authentication bypass (CWE-288) that allows remote, unauthenticated attackers to access and leak stored credential data from the system. The vulnerability stems from an alternate path or channel that circumvents established authentication mechanisms.

Business impact

The severity of this vulnerability is rated as critical with a CVSS score of 9.5, reflecting the high potential for unauthorized data access. Because Ivanti EPM typically manages enterprise-wide assets with elevated privileges, the exposure of stored credentials presents a severe risk of lateral movement, privilege escalation, and total system compromise. Successful exploitation could lead to widespread unauthorized access across the target network, causing significant operational and security repercussions.

Remediation

Immediate Action: Update all instances of Ivanti Endpoint Manager to version 2024 SU5 or later immediately.

Proactive Monitoring: Review access logs for unusual, unauthorized API calls or unexpected authentication attempts targeting credential storage endpoints.

Compensating Controls: Implement strict network segmentation and restrict access to the EPM management interface to trusted administrative subnets only.

Exploitation status

Public Exploit Available: Yes, a Nuclei detection template exists.

Analyst recommendation

Due to the critical severity and confirmed active exploitation, this vulnerability poses an immediate threat to your infrastructure. Organizations must prioritize patching to version 2024 SU5 without delay. If immediate patching is not possible, ensure that the EPM management interface is isolated from public-facing networks to mitigate the risk of remote exploitation.

More Ivanti CVEs

Sources