CVE-2026-1603 PUBLISHED

Assigner: ivanti
Reserved: 29.01.2026 Published: 10.02.2026 Updated: 10.02.2026

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 8.6

Product Status

Vendor Ivanti
Product Endpoint Manager
Versions Default: affected
  • Version 2024 SU5 is unaffected

References

Problem Types

  • CWE-288: Authentication Bypass Using an Alternate Path or Channel CWE

Impacts

  • CAPEC-115 Authentication Bypass