
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8109 is an information disclosure vulnerability in Ivanti Endpoint Manager (EPM) caused by an exposed dangerous method in the RemoteControlAuth module on the Core Server. It allows remote authenticated attackers to leak stored access credentials, potentially enabling further compromise. The vulnerability affects all Ivanti EPM versions prior to 2024 SU6, including the 2022 release line and all 2024 service update variants up to SU5. Disclosed on May 12, 2026, it carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Feedly).
The root cause is classified as CWE-749 (Exposed Dangerous Method or Function): the RemoteControlAuth module on the EPM Core Server exposes a method that should be restricted but is accessible to any authenticated network user (GitHub Advisory). An attacker with low-level authenticated access can invoke this method remotely over the network without user interaction, causing the server to return stored access credentials. Notably, the existing authentication mechanism can be bypassed, lowering the effective barrier to exploitation (Feedly). The ZDI advisory (ZDI-26-308) corroborates the specific flaw location within the RemoteControlAuth module (ZDI Advisory).
Successful exploitation results in the disclosure of stored access credentials from the Ivanti EPM Core Server, with high confidentiality impact and no effect on integrity or availability. Leaked credentials could be leveraged for lateral movement within the enterprise environment, privilege escalation, or unauthorized access to managed endpoints — all systems under EPM's administrative scope. Given EPM's role as an enterprise endpoint management platform, credential exposure could grant attackers broad access to managed devices across the organization (GitHub Advisory, Feedly).
RemoteControlAuth module on the EPM Core Server, targeting the exposed dangerous method that lacks proper access controls.RemoteControlAuth endpoints from non-administrative accounts or unexpected source IPs.RemoteControlAuth module from low-privileged accounts; authentication events from accounts that do not normally interact with remote control functions.Ivanti has released a patch in Ivanti Endpoint Manager 2024 SU6, which resolves this vulnerability; upgrading to this version or later is the recommended remediation (GitHub Advisory, Ivanti Advisory). As interim mitigations, administrators should restrict network access to the EPM Core Server to authorized administrators only, reducing the attack surface for low-privileged users. Additionally, organizations should review credential exposure logs and rotate any credentials that may have been accessible via the RemoteControlAuth module.
Ivanti issued a security advisory in May 2026 addressing this and other vulnerabilities across EPM, Secure Access, Xtraction, and Virtual Traffic Manager products (Ivanti Advisory). Security news outlets including CyberSecurityNews and HealSecurity covered the broader Ivanti patch release, noting multiple vulnerabilities addressed simultaneously. The ZDI published advisory ZDI-26-308 attributing discovery to their researchers (ZDI Advisory). Community reaction has been moderate, consistent with a medium-severity credential disclosure issue without active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."