VDB

GCVE-110-NCSC-2026-59

GCVE-110-NCSC-2026-59
Advisory PublishedCVSS 8.6/10
Vulnetix · Advisory published February 11, 2026
Ivanti Endpoint Manager versions prior to 2024 SU5 contain an authentication bypass vulnerability that allows remote unauthenticated attackers to leak stored credential data due to improper access control.

Weaknesses (CWE)

CWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Risk Scores

CVSS 3.1
8.6/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
Ivantivers:unknown/*

References

advisory
advisory
advisory
exploit
advisory

Browse GCVE Records

74,132 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›