Ivanti Endpoint Manager - Authentication Bypass
CVE-2026-1603
Verified
Description
Ivanti Endpoint Manager < 2024 SU5 contains an authentication bypass caused by improper access control, letting remote unauthenticated attackers leak stored credential data, exploit requires no special privileges.
Severity
High
CVSS Score
8.6
Exploit Probability
88%
Affected Product
endpoint_manager
Published Date
February 13, 2026
Template Author
dhiyaneshdk, watchtowrlabs
CVE-2026-1603.yaml
8.6Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVE ID:
cve-2026-1603
CWE ID:
cwe-288
Remediation Steps
Update to version 2024 SU5 or later.