← Vulnerability feed

Vulnerability record · CVE-2026-1603 · published 10 February 2026

CVE-2026-1603: Ivanti Endpoint Manager authentication bypass leaks stored credentials

Ivanti · Endpoint Manager

Ivanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a function that leaks specific stored credential data. Because the flaw requires no credentials or user interaction and exposes secrets, it is a serious pre-auth information disclosure in an endpoint management platform.

7.5 CVSS 3.1 High CISA KEV since 9 Mar 2026 EPSS 88% · top 0.2% CWE-288 · Authentication bypass via alternate pathCWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityIt is a pre-auth remote authentication bypass leaking stored credentials, listed in CISA KEV with a very high EPSS score, so exploitation is known and impact is significant.

What it is

Ivanti Endpoint Manager before 2024 SU5 contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker reach a function that leaks specific stored credential data. Because the flaw requires no credentials or user interaction and exposes secrets, it is a serious pre-auth information disclosure in an endpoint management platform.

Impact

An attacker gains access to stored credential data held by Endpoint Manager, which can enable lateral movement or further compromise of managed endpoints and connected systems. The flaw is confidentiality-only; there is no reported integrity or availability impact.

Attack surface

Reachable over the network via an alternate path that skips authentication, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

Listed in CISA KEV (added 2026-03-09, due 2026-03-23), indicating known exploitation in the wild, and EPSS is very high at 0.8056 (99.6th percentile). No ransomware campaign use is documented.

What to do

  • Upgrade Ivanti Endpoint Manager to 2024 SU5 or later; this is the primary fix.
  • If immediate patching is not possible, apply the mitigations in Ivanti's February 2026 security advisory or discontinue use of the product per CISA BOD 22-01 guidance.
  • Restrict network access to Endpoint Manager management interfaces to trusted hosts or management networks.
  • Rotate or review credentials stored in Endpoint Manager, since the flaw leaks stored credential data.
  • Monitor for and investigate any unauthorized access to EPM services before patching completes.

Detection

  • Review EPM server and web logs for unauthenticated requests to endpoints or paths that should require authentication.
  • Alert on anomalous access to credential or secret retrieval functions within Endpoint Manager.
  • Hunt for outbound connections from the EPM server to unexpected destinations that could indicate exfiltration of leaked credentials.
  • Correlate EPM access logs with authentication logs to find sessions that retrieved data without a corresponding login.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-1603 to the Known Exploited Vulnerabilities catalog on 9 March 2026 as "Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 23 March 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-1603 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-29824Ivanti Endpoint Manager Core Server SQL Injection Enables RCEIvanti Endpoint Manager 2022 SU5 and earlier contains an unspecified SQL injection in the Core server. An unauthenticated attacker on the same networ…KEVEPSS 100%analysed7.5CVE-2024-13159Ivanti EPM absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 100%analysed7.5CVE-2024-13160Ivanti Endpoint Manager absolute path traversal information leakIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that allows a remote, unauthenticated attacker to read files outside …KEVEPSS 91%analysed7.5CVE-2024-13161Ivanti Endpoint Manager absolute path traversal leaks sensitive filesIvanti Endpoint Manager (EPM) contains an absolute path traversal flaw (CWE-36) that lets a remote attacker read files outside the intended directory…KEVEPSS 90%analysed9.9CVE-2020-13774Ivanti endpoint manager unrestricted file upload vulnerabilityAn unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…EPSS 5.0%9.8CVE-2024-50330Ivanti endpoint manager sql injection vulnerabilitySQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated at…EPSS 40%9.8CVE-2024-29847Ivanti EPM agent portal deserialization allows unauthenticated RCEThe agent portal in Ivanti Endpoint Manager (EPM) deserializes untrusted data, allowing a remote unauthenticated attacker to execute code. The flaw a…EPSS 53%analysed9.8CVE-2024-8191Ivanti endpoint manager sql injection vulnerabilitySQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achie…EPSS 20%

Source: NIST National Vulnerability Database (record CVE-2026-1603), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.