PT-2026-70214 · Ivanti · Endpoint Manager
CVE-2026-18127
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Ivanti Endpoint Manager versions prior to 2024 SU7
Description
An issue in the Core of the software allows a remote authenticated attacker to gain full write control over an S3 bucket used for session recording storage. This is caused by external control of a filename, which enables a path traversal attack, allowing the attacker to manipulate file paths to access or modify files outside the intended directory.
Recommendations
Update to version 2024 SU7 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Endpoint Manager