Executive brief
Ivanti Endpoint Manager, a platform used by organizations to manage and secure various devices across their network, contains a security flaw that allows unauthorized access. An attacker can bypass security checks to steal sensitive stored credentials without needing a username or password. This vulnerability is currently being exploited in the wild, posing a significant risk of unauthorized access to corporate systems and data.
Technical details
An authentication bypass vulnerability (CWE-288/CWE-306) exists in Ivanti Endpoint Manager (EPM) prior to version 2024 SU5. The flaw involves an alternate path or channel that allows a remote, unauthenticated attacker to bypass standard authentication mechanisms. Successful exploitation enables the attacker to leak specific stored credential data from the system. This vulnerability is confirmed to be exploited in the wild and is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Users are advised to update to version 2024 SU5 or later.
Affected products
- Ivanti Endpoint Manager (EPM) Before 2024 SU5
Timeline
- 2026-02-10: disclosed: Initial disclosure by Ivanti
- 2026-02-10: advisory: NVD published date
- 2026-03-09: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-03-09: exploited: Confirmed active exploitation in the wild