/Vulnerability Library

Ivanti Endpoint Manager - Authentication Bypass

CVE-2026-1603
Verified

Description

Ivanti Endpoint Manager < 2024 SU5 contains an authentication bypass caused by improper access control, letting remote unauthenticated attackers leak stored credential data, exploit requires no special privileges.

Severity

High

CVSS Score

8.6

Exploit Probability

88%

Affected Product

endpoint_manager

Published Date

February 13, 2026

Template Author

dhiyaneshdk, watchtowrlabs

CVE-2026-1603.yaml
8.6Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVE ID:
cve-2026-1603
CWE ID:
cwe-288

References

https://x.com/watchtowrcyber/status/2022305033086235108/photo/1https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024https://nvd.nist.gov/vuln/detail/CVE-2026-1603

Remediation Steps

Update to version 2024 SU5 or later.