Executive brief
Ivanti Virtual Traffic Manager, a solution used to manage and optimize application traffic, is vulnerable to a security flaw that allows an administrator to execute unauthorized commands on the underlying system. If exploited, an attacker with administrative credentials could take full control of the appliance, potentially leading to data theft or service disruption. This issue is resolved in version 22.9r4 and later.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Ivanti Virtual Traffic Manager (vTM) management interface. The flaw is caused by improper neutralization of special elements used in OS commands within the appliance's administrative components. A remote attacker with high privileges (admin) can exploit this vulnerability over the network without user interaction to execute arbitrary code with the privileges of the underlying operating system. Ivanti has released version 22.9r4 to address this vulnerability.
Affected products
- Ivanti Virtual Traffic Manager (vTM) before 22.9r4
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory