Sensitive Information Exposure in Ivanti Endpoint Manager
CVE-2026-18129

8.1HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18129?

A security vulnerability exists in Ivanti Endpoint Manager prior to version 2024 SU7, where sensitive information is transmitted in cleartext. An unauthenticated remote attacker with a man-in-the-middle (MITM) capability can exploit this flaw to intercept and leak credentials utilized for external SQL connections, potentially compromising the integrity and confidentiality of sensitive data.

Affected Version(s)

Endpoint Manager 2024 SU7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.