Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su1:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su2:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su3:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su3_security_release_1:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su4:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su4_security_release_1:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su5:*:*:*:*:*:* |
Tue, 12 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Authenticated Credential Leakage via Exposed Method in Ivanti Endpoint Manager | |
| First Time appeared |
Ivanti
Ivanti endpoint Manager |
|
| Vendors & Products |
Ivanti
Ivanti endpoint Manager |
Tue, 12 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials. | |
| Weaknesses | CWE-749 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ivanti
Published:
Updated: 2026-05-12T18:58:58.165Z
Reserved: 2026-05-07T16:20:42.642Z
Link: CVE-2026-8109
Updated: 2026-05-12T18:58:52.388Z
Status : Analyzed
Published: 2026-05-12T15:16:17.420
Modified: 2026-05-12T19:18:29.283
Link: CVE-2026-8109
No data.
OpenCVE Enrichment
Updated: 2026-05-12T16:30:19Z