File Control Vulnerability in Ivanti Endpoint Manager Software
CVE-2026-18127

7.7HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18127?

The vulnerability allows remote authenticated attackers to gain full write control over an Amazon S3 bucket configured for session recording storage within Ivanti Endpoint Manager versions prior to 2024 SU7. This could lead to unauthorized modifications and exposure of sensitive session data, putting organizational security at risk.

Affected Version(s)

Endpoint Manager 2024 SU7

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.