CVE-2026-18129 – Ivanti Endpoint Manager
“Three high-impact flaws put credentials, endpoint availability, and session-storage integrity at risk.”
Ivanti Endpoint Manager before version 2024 SU7 is affected by three High-severity vulnerabilities. CVE-2026-18129 exposes external SQL credentials to a remote unauthenticated attacker in a MITM position. The CVSS score is 8.1, which is High severity. CVE-2026-18125 allows a remote unauthenticated attacker to crash the Agent service. The CVSS score is 7.5, which is High severity. CVE-2026-18127 allows a remote authenticated attacker to gain full write control over an S3 bucket used for session recording. The CVSS score is 7.7, which is High severity.
Ivanti Endpoint Manager 2024 SU7 addresses these issues across the Core and Agent components.
Key Details
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-295