Ivanti Automation
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Ivanti Automation.
By the Year
In 2026 there have been 2 vulnerabilities in Ivanti Automation with an average score of 8.7 out of ten. Automation did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 8.65 |
| 2025 | 0 | 0.00 |
| 2024 | 1 | 7.80 |
| 2023 | 1 | 7.80 |
It may take a day or so for new Automation vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Ivanti Automation Security Vulnerabilities
Landray OA Unauth HQL Injection via wechatLoginHelper.do
CVE-2024-58352
7.5 - High
- July 02, 2026
Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes by injecting malicious HQL syntax into the uid POST parameter of the wechatLoginHelper.do endpoint. Attackers can exploit the lack of input sanitization in the string-concatenated filter expression passed to the Hibernate findList() call to extract sensitive data such as administrator password hashes and, with sufficient database privileges, perform file-write operations enabling remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-03-11 (UTC).
SQL Injection: Hibernate
Kofax Capture 6.0.0.0 Unauth .NET Remoting RCE via HTTP port 2424
CVE-2026-23751
9.8 - Critical
- April 23, 2026
Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that is accessible without authentication and uses a default, publicly known endpoint identifier. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling techniques to instantiate a remote System.Net.WebClient object and read arbitrary files from the server filesystem, write attacker-controlled files to the server, or coerce NTLMv2 authentication to an attacker-controlled host, enabling sensitive credential disclosure, denial of service, remote code execution, or lateral movement depending on service account privileges and network environment.
Missing Authentication for Critical Function
Ivanti Automation Local Privilege Escalation via Insecure Permissions
CVE-2024-9845
7.8 - High
- December 11, 2024
Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.
Incorrect Default Permissions
Windows Auth Bypass via Insecure IPC (CVE-2022-44569)
CVE-2022-44569
7.8 - High
- November 03, 2023
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
authentification
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Ivanti Automation or by Ivanti? Click the Watch button to subscribe.