Back

MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database

Published Feb 10, 2026

Description

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (3)
  1. CISA ADP
    • SSVC technical impact

      changed from total to partial

  2. CISA ADP
    • SSVC technical impact

      changed from partial to total

  3. CISA ADP
    • SSVC technical impact

      changed from total to partial

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ivanti
Published Feb 10, 2026
Updated Feb 26, 2026
Reserved Jan 29, 2026

CISA Vulnrichment

Updated Feb 10, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner ivanti
Published Feb 10, 2026
Updated Feb 26, 2026

GitHub

No data