CVE-2026-8110
Ivanti Endpoint Manager vulnerability analysis and mitigation

Overview

CVE-2026-8110 is a privilege escalation vulnerability caused by incorrect permissions assignment in the agent component of Ivanti Endpoint Manager (EPM). A local authenticated attacker with low-level privileges can exploit this flaw to escalate their privileges on affected systems. The vulnerability affects all versions of Ivanti Endpoint Manager up to and including 2024 SU5, with the fix introduced in version 2024 SU6. It was published on May 12, 2026, and carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Ivanti Advisory).

Technical details

The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource), where the Ivanti EPM agent assigns overly permissive access controls to security-critical resources, enabling unintended actors to read or modify them (GitHub Advisory). The attack vector is local, requiring the attacker to already have authenticated access to the system with low privileges — no user interaction or elevated starting privileges are needed. By abusing the misconfigured permissions on agent-related resources, a local user can manipulate those resources to gain higher-level system access. No public proof-of-concept or detailed technical write-up has been identified at this time (Feedly).

Impact

Successful exploitation allows a local authenticated attacker to escalate privileges to a high level, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive files managed by the EPM agent, modify configurations or binaries, and potentially disrupt endpoint management operations. While the attack scope is unchanged (limited to the local system), privilege escalation on an endpoint management agent could facilitate further lateral movement across managed endpoints in the environment (GitHub Advisory, Ivanti Advisory).

Mitigation and workarounds

Ivanti has released a patch in Ivanti Endpoint Manager version 2024 SU6, which resolves this vulnerability (Ivanti Advisory). Organizations should prioritize upgrading to 2024 SU6 or later as the primary remediation step. In environments where immediate patching is not feasible, administrators should implement strict local access controls to limit which users can authenticate to systems running the EPM agent, and monitor for unauthorized privilege escalation attempts (Feedly).

Community reactions

Coverage of CVE-2026-8110 was part of broader reporting on Ivanti's May 2026 security advisory, which addressed multiple vulnerabilities across EPM, Secure Access, Xtraction, and Virtual Traffic Manager. Security news outlets including CyberSecurityNews and HealSecurity covered the patch release, and the Belgian Centre for Cybersecurity (CCB) issued a warning advisory (CCB Advisory). Community reaction was measured, with no significant controversy or notable researcher commentary specific to this CVE, consistent with the absence of active exploitation or a public PoC.

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8111HIGH8.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-8110HIGH7.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1603HIGH7.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
YesNoFeb 10, 2026
CVE-2026-8109MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1602MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management