Executive brief
Ivanti Endpoint Manager is a centralized platform used by IT departments to manage and secure various devices across an organization. A vulnerability in the Core Server component allows a logged-in user to access sensitive credentials that they should not be able to see. This could allow an attacker with basic access to escalate their privileges or gain unauthorized access to other systems within the corporate network.
Technical details
A vulnerability classified as CWE-749 (Exposed Dangerous Method or Function) exists in the Core Server of Ivanti Endpoint Manager (EPM). The flaw is located in an exposed method that does not properly restrict access to sensitive information. A remote attacker with low-level authenticated access can invoke this method to retrieve access credentials. The issue affects all versions prior to 2024 SU6. Ivanti has released a patch in the 2024 SU6 update to address this exposure.
Affected products
- Ivanti Endpoint Manager (EPM) Before 2024 SU6
Timeline
- 2026-05-12: advisory: Initial advisory published by Ivanti and NVD
- 2026-05-12: patched: Fix available in version 2024 SU6