
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8111 is a SQL injection vulnerability in the web console of Ivanti Endpoint Manager (EPM) that allows a remote authenticated attacker with low-level privileges to achieve remote code execution. It affects all EPM versions before 2024 SU6, including EPM 2024 SU1 through SU5 and versions up to and including 2022. The vulnerability was published on May 12, 2026, with a patch released in EPM 2024 SU6. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Ivanti Advisory).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input in the EPM web console is not properly sanitized before being incorporated into SQL queries (GitHub Advisory). An attacker with low-level authenticated access can craft malicious SQL input through the web console interface to manipulate backend database queries, ultimately escalating to remote code execution — likely via database-native command execution features (e.g., xp_cmdshell on MSSQL). No user interaction is required beyond authentication, and the attack is conducted entirely over the network with low complexity (GitHub Advisory). No public proof-of-concept code has been identified at this time.
Successful exploitation grants a remote authenticated attacker full remote code execution on the EPM server, resulting in high impact to confidentiality, integrity, and availability. An attacker could exfiltrate sensitive endpoint management data (including device inventories, credentials, and configurations), modify or destroy data, and disrupt EPM services. Given EPM's role as a centralized endpoint management platform, a compromised server could serve as a pivot point for lateral movement across the managed environment (GitHub Advisory, Ivanti Advisory).
xp_cmdshell on Microsoft SQL Server) to execute operating system commands on the EPM server.', --, UNION, xp_cmdshell) in query parameters or POST body fields; database error messages logged in application logs indicating malformed queries.cmd.exe, powershell.exe, net.exe) with unusual arguments..aspx or .ashx extensions); unexpected scripts or executables in temp directories.xp_cmdshell or enabling of advanced options; new SQL Server logins or privilege escalation events.Ivanti has released a patch in EPM 2024 SU6, which resolves this vulnerability; organizations should upgrade immediately (Ivanti Advisory). As interim mitigations, restrict network access to the EPM web console to trusted IP ranges only, and enforce the principle of least privilege by limiting user accounts to only those permissions necessary for operations. Monitor web console and database logs for suspicious SQL injection patterns. Organizations running EPM 2022 or earlier should prioritize upgrading to a supported and patched release.
The vulnerability was covered by cybersecurity news outlets including CyberSecurityNews and HealSecurity as part of broader Ivanti May 2026 patch coverage (CyberSecurityNews). The Belgian Centre for Cybersecurity (CCB) issued a warning advisory regarding Ivanti's May 2026 security updates. Community aggregators including Vulners, VulDB, and CVEFeed indexed the vulnerability shortly after disclosure, and Qualys published detection guidance as part of its May 2026 application security detections summary. No notable researcher commentary or significant social media debate has been identified beyond routine disclosure coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."