SQL Injection in Ivanti Endpoint Manager Exposes Sensitive Data
CVE-2026-1602
6.5MEDIUM
What is CVE-2026-1602?
An SQL injection vulnerability in Ivanti Endpoint Manager prior to version 2024 SU5 permits a remote authenticated attacker to execute unauthorized queries, allowing access to read arbitrary data from the underlying database. This flaw can potentially lead to data exposure and compromise sensitive information, highlighting the need for immediate updates to safeguard against such attacks.
Affected Version(s)
Endpoint Manager 2024 SU5