CVE-2026-8109
Ivanti Endpoint Manager vulnerability analysis and mitigation

Overview

CVE-2026-8109 is an information disclosure vulnerability in Ivanti Endpoint Manager (EPM) caused by an exposed dangerous method in the RemoteControlAuth module on the Core Server. It allows remote authenticated attackers to leak stored access credentials, potentially enabling further compromise. The vulnerability affects all Ivanti EPM versions prior to 2024 SU6, including the 2022 release line and all 2024 service update variants up to SU5. Disclosed on May 12, 2026, it carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Feedly).

Technical details

The root cause is classified as CWE-749 (Exposed Dangerous Method or Function): the RemoteControlAuth module on the EPM Core Server exposes a method that should be restricted but is accessible to any authenticated network user (GitHub Advisory). An attacker with low-level authenticated access can invoke this method remotely over the network without user interaction, causing the server to return stored access credentials. Notably, the existing authentication mechanism can be bypassed, lowering the effective barrier to exploitation (Feedly). The ZDI advisory (ZDI-26-308) corroborates the specific flaw location within the RemoteControlAuth module (ZDI Advisory).

Impact

Successful exploitation results in the disclosure of stored access credentials from the Ivanti EPM Core Server, with high confidentiality impact and no effect on integrity or availability. Leaked credentials could be leveraged for lateral movement within the enterprise environment, privilege escalation, or unauthorized access to managed endpoints — all systems under EPM's administrative scope. Given EPM's role as an enterprise endpoint management platform, credential exposure could grant attackers broad access to managed devices across the organization (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify Ivanti EPM Core Server instances exposed on the network using asset inventory tools or network scanners; confirm the version is prior to 2024 SU6.
  2. Authentication: Obtain or use any low-privileged authenticated account on the EPM system — the authentication mechanism can be bypassed, further lowering the access requirement.
  3. Invoke exposed method: Send a crafted network request to the RemoteControlAuth module on the EPM Core Server, targeting the exposed dangerous method that lacks proper access controls.
  4. Extract credentials: Parse the server's response to retrieve stored access credentials (e.g., service account passwords, remote control authentication tokens) returned by the exposed method.
  5. Leverage credentials: Use the disclosed credentials for lateral movement, privilege escalation, or unauthorized access to endpoints managed by the EPM platform (ZDI Advisory, Feedly).

Indicators of compromise

  • Network: Unusual or repeated authenticated requests to the EPM Core Server targeting RemoteControlAuth endpoints from non-administrative accounts or unexpected source IPs.
  • Logs: EPM Core Server access logs showing authenticated API calls to the RemoteControlAuth module from low-privileged accounts; authentication events from accounts that do not normally interact with remote control functions.
  • Behavioral: Credential use from accounts that have not previously authenticated to downstream systems; unexpected remote control sessions initiated shortly after access to the EPM Core Server.
  • Scanner Detections: Alerts from Qualys (detection IDs 387376, 531377) or Nessus (plugin ID 314922) indicating the presence of the vulnerable EPM version (Feedly).

Mitigation and workarounds

Ivanti has released a patch in Ivanti Endpoint Manager 2024 SU6, which resolves this vulnerability; upgrading to this version or later is the recommended remediation (GitHub Advisory, Ivanti Advisory). As interim mitigations, administrators should restrict network access to the EPM Core Server to authorized administrators only, reducing the attack surface for low-privileged users. Additionally, organizations should review credential exposure logs and rotate any credentials that may have been accessible via the RemoteControlAuth module.

Community reactions

Ivanti issued a security advisory in May 2026 addressing this and other vulnerabilities across EPM, Secure Access, Xtraction, and Virtual Traffic Manager products (Ivanti Advisory). Security news outlets including CyberSecurityNews and HealSecurity covered the broader Ivanti patch release, noting multiple vulnerabilities addressed simultaneously. The ZDI published advisory ZDI-26-308 attributing discovery to their researchers (ZDI Advisory). Community reaction has been moderate, consistent with a medium-severity credential disclosure issue without active exploitation.

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8111HIGH8.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-8110HIGH7.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1603HIGH7.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
YesNoFeb 10, 2026
CVE-2026-8109MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1602MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management