Vulnerability record · CVE-2026-1603 · published 10 February 2026
CVE-2026-1603: Ivanti Endpoint Manager authentication bypass leaks stored credentials
Ivanti · Endpoint Manager
Ivanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a function that leaks specific stored credential data. Because the flaw requires no credentials or user interaction and exposes secrets, it is a serious pre-auth information disclosure in an endpoint management platform.
Description
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityIt is a pre-auth remote authentication bypass leaking stored credentials, listed in CISA KEV with a very high EPSS score, so exploitation is known and impact is significant.
What it is
Ivanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a function that leaks specific stored credential data. Because the flaw requires no credentials or user interaction and exposes secrets, it is a serious pre-auth information disclosure in an endpoint management platform.
Impact
An attacker gains access to stored credential data held by Endpoint Manager, which can enable lateral movement or further compromise of managed endpoints and connected systems. The flaw is confidentiality-only; there is no reported integrity or availability impact.
Attack surface
Reachable over the network via an alternate path that skips authentication, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
Listed in CISA KEV (added 2026-03-09, due 2026-03-23), indicating known exploitation in the wild, and EPSS is very high at 0.8056 (99.6th percentile). No ransomware campaign use is documented.
What to do
- Upgrade Ivanti Endpoint Manager to 2024 SU5 or later; this is the primary fix.
- If immediate patching is not possible, apply the mitigations in Ivanti's February 2026 security advisory or discontinue use of the product per CISA BOD 22-01 guidance.
- Restrict network access to Endpoint Manager management interfaces to trusted hosts or management networks.
- Rotate or review credentials stored in Endpoint Manager, since the flaw leaks stored credential data.
- Monitor for and investigate any unauthorized access to EPM services before patching completes.
Detection
- Review EPM server and web logs for unauthenticated requests to endpoints or paths that should require authentication.
- Alert on anomalous access to credential or secret retrieval functions within Endpoint Manager.
- Hunt for outbound connections from the EPM server to unexpected destinations that could indicate exfiltration of leaked credentials.
- Correlate EPM access logs with authentication logs to find sessions that retrieved data without a corresponding login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-1603 to the Known Exploited Vulnerabilities catalog on 9 March 2026 as "Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1603 | US Government Resource |
Track CVE-2026-1603 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-1603), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.