CVE-2026-8109 Details
Description
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
A vulnerability exists in the Core Server of Ivanti Endpoint Manager in versions through 2024 SU5. This vulnerability allows remote authenticated attackers to leak access credentials by exploiting an exposed dangerous method.
Users can update to Ivanti Endpoint Manager 2024 SU6, which is available for download through the Ivanti License System (ILS).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-May-2026?language=en_US | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-749 | Exposed Dangerous Method or Function | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | <= 2022 2024 - 2024 su1 2024 su2 2024 su3 2024 su3_security_release_1 2024 su4 2024 su4_security_release_1 2024 su5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | ivanti |