CVE-2026-8111 Details
Description
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.
A SQL injection vulnerability has been identified in the web console of Ivanti Endpoint Manager, affecting versions through 2024 SU5. This vulnerability allows remote authenticated attackers to execute arbitrary code on the server.
Users can update to Ivanti Endpoint Manager 2024 SU6 to address this vulnerability. The update is available through the Ivanti License System (ILS).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-May-2026?language=en_US | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti endpoint manager | <= 2022 2024 - 2024 su1 2024 su2 2024 su3 2024 su3_security_release_1 2024 su4 2024 su4_security_release_1 2024 su5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | ivanti |