Junglewise Threat Intelligence

CVE-2026-8111: Ivanti Endpoint Manager SQL injection in web console

CVE-2026-8111 · Severity: high · CVSS 8.8 · Published 2026-05-12

Technologies: Ivanti Endpoint Manager, Ivanti Endpoint Manager (EPM). Vendors: Ivanti.

Executive brief

Ivanti Endpoint Manager is a centralized console used by IT departments to manage and secure devices across a corporate network. A security vulnerability in its web-based management interface allows an attacker with basic user credentials to execute unauthorized commands on the server. This could lead to a complete takeover of the management system, potentially allowing the attacker to compromise all connected devices or disrupt business operations.

Technical details

A SQL injection vulnerability (CWE-89) exists in the web console component of Ivanti Endpoint Manager (EPM). The flaw is caused by improper neutralization of special elements within SQL commands processed by the web interface. A remote attacker with low-privileged authentication can exploit this by sending specially crafted requests to the web console, leading to arbitrary remote code execution (RCE) on the EPM core server. The vulnerability affects versions prior to 2024 SU6, including the 2022 release branch and 2024 releases up to SU5. Ivanti has released version 2024 SU6 to address this issue.

Affected products

  • Ivanti Endpoint Manager (EPM) Before 2024 SU6, including 2022 and 2024 versions up to SU5

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: Vendor advisory published by Ivanti

References

Related threats