Exposed method in Ivanti Endpoint Mgmt Core Server leaks credentials
CVE-2026-8109 Published on May 12, 2026
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
Vulnerability Analysis
CVE-2026-8109 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Exposed Dangerous Method or Function
The software provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Products Associated with CVE-2026-8109
Want to know whenever a new CVE is published for Ivanti Endpoint Manager? stack.watch will email you.