Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 12 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su1:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su2:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su3:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su3_security_release_1:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su4:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su4_security_release_1:*:*:*:*:*:* cpe:2.3:a:ivanti:endpoint_manager:2024:su5:*:*:*:*:*:* |
Tue, 12 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via SQL Injection in Ivanti Endpoint Manager Web Console | |
| First Time appeared |
Ivanti
Ivanti endpoint Manager |
|
| Vendors & Products |
Ivanti
Ivanti endpoint Manager |
Tue, 12 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ivanti
Published:
Updated: 2026-05-13T03:57:54.231Z
Reserved: 2026-05-07T16:20:44.212Z
Link: CVE-2026-8111
Updated: 2026-05-12T19:00:31.810Z
Status : Analyzed
Published: 2026-05-12T15:16:18.923
Modified: 2026-05-12T19:17:48.713
Link: CVE-2026-8111
No data.
OpenCVE Enrichment
Updated: 2026-05-12T16:30:19Z