CVE-2026-8111

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

high 8.8 CVSS 3.1
Published: May 12, 2026
Modified: May 12, 2026
Vendor: Ivanti
Product: Endpoint Manager
Versions: 2024

Description

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

References

Related CVEs