CVE-2026-1603
EUVD-2026-684210.02.2026, 16:16
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ivanti | endpoint_manager | 𝑥 < 2024 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-288 - Authentication Bypass Using an Alternate Path or ChannelA product requires authentication, but the product has an alternate path or channel that does not require authentication.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.