PT-2026-7269 · Ivanti · Ivanti Endpoint Manager

CVE-2026-1602

·

Publicado

2026-02-09

·

Atualizado

2026-02-13

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager versions prior to 2024 SU5
Description A SQL injection issue exists in Ivanti Endpoint Manager. A remote authenticated attacker can potentially read arbitrary data from the database through this flaw.
Recommendations Update Ivanti Endpoint Manager to version 2024 SU5 or later.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-01854
CVE-2026-1602
ZDI-26-079

Produtos afetados

Ivanti Endpoint Manager