Remote Credential Leak in Ivanti Endpoint Manager by Ivanti
CVE-2026-8109

6.5MEDIUM

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
12 May 2026

What is CVE-2026-8109?

An exposed dangerous method in the Core Server of Ivanti Endpoint Manager prior to version 2024 SU6 presents a significant security risk. This vulnerability allows remote authenticated attackers to potentially leak access credentials, which could be exploited to gain unauthorized access to sensitive information and systems.

Affected Version(s)

Endpoint Manager 2024 SU6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.