CVE-2026-8051 Details
Description
OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
A command injection vulnerability has been identified in Ivanti Virtual Traffic Manager (vTM) versions through 22.9r3. This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary code on the server.
Users can update to Ivanti Virtual Traffic Manager version 22.9r4 to address this vulnerability. The update is available through the Ivanti License System (ILS).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2026-8051?language=en_US | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti virtual traffic manager | <= 22.8 22.9 r1 22.9 r2 22.9 r3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | ivanti |