CVE-2026-18127 PUBLISHED

Assigner: ivanti
Reserved: 28.07.2026 Published: 11.08.2026 Updated: 11.08.2026

External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
CVSS Score: 7.7

Product Status

Vendor Ivanti
Product Endpoint Manager
Versions Default: affected
  • Version 2024 SU7 is unaffected

References

Problem Types

  • CWE-73 External control of file name or path CWE

Impacts

  • CAPEC-122 Privilege Abuse