CVE-2026-8111
Ivanti Endpoint Manager vulnerability analysis and mitigation

Overview

CVE-2026-8111 is a SQL injection vulnerability in the web console of Ivanti Endpoint Manager (EPM) that allows a remote authenticated attacker with low-level privileges to achieve remote code execution. It affects all EPM versions before 2024 SU6, including EPM 2024 SU1 through SU5 and versions up to and including 2022. The vulnerability was published on May 12, 2026, with a patch released in EPM 2024 SU6. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Ivanti Advisory).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input in the EPM web console is not properly sanitized before being incorporated into SQL queries (GitHub Advisory). An attacker with low-level authenticated access can craft malicious SQL input through the web console interface to manipulate backend database queries, ultimately escalating to remote code execution — likely via database-native command execution features (e.g., xp_cmdshell on MSSQL). No user interaction is required beyond authentication, and the attack is conducted entirely over the network with low complexity (GitHub Advisory). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation grants a remote authenticated attacker full remote code execution on the EPM server, resulting in high impact to confidentiality, integrity, and availability. An attacker could exfiltrate sensitive endpoint management data (including device inventories, credentials, and configurations), modify or destroy data, and disrupt EPM services. Given EPM's role as a centralized endpoint management platform, a compromised server could serve as a pivot point for lateral movement across the managed environment (GitHub Advisory, Ivanti Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible Ivanti EPM web console instances running versions prior to 2024 SU6 using network scanning tools (e.g., Shodan, Censys, or internal network scanners).
  2. Authentication: Obtain low-privilege credentials to the EPM web console through phishing, credential stuffing, or other means — only basic authenticated access is required.
  3. Identify injectable parameter: Navigate the EPM web console to identify input fields or API endpoints that interact with the backend database and are susceptible to SQL injection.
  4. Craft SQL injection payload: Inject malicious SQL syntax into the vulnerable parameter to manipulate the underlying SQL query (e.g., using UNION-based, error-based, or stacked queries depending on the database configuration).
  5. Escalate to RCE: Leverage database-level command execution capabilities (e.g., enabling and invoking xp_cmdshell on Microsoft SQL Server) to execute operating system commands on the EPM server.
  6. Establish persistence: Deploy a web shell, create a backdoor account, or establish a reverse shell to maintain access and facilitate further lateral movement across managed endpoints (GitHub Advisory).

Indicators of compromise

  • Network: Unusual outbound connections from the EPM server to unknown external IP addresses; unexpected inbound connections to the EPM web console from anomalous source IPs.
  • Logs: EPM web console access logs showing requests with SQL metacharacters (e.g., ', --, UNION, xp_cmdshell) in query parameters or POST body fields; database error messages logged in application logs indicating malformed queries.
  • Process: Unexpected child processes spawned by the EPM web server or SQL Server process (e.g., cmd.exe, powershell.exe, net.exe) with unusual arguments.
  • File System: New or modified files in the EPM web root directory (e.g., web shells with .aspx or .ashx extensions); unexpected scripts or executables in temp directories.
  • Database: SQL Server audit logs showing execution of xp_cmdshell or enabling of advanced options; new SQL Server logins or privilege escalation events.

Mitigation and workarounds

Ivanti has released a patch in EPM 2024 SU6, which resolves this vulnerability; organizations should upgrade immediately (Ivanti Advisory). As interim mitigations, restrict network access to the EPM web console to trusted IP ranges only, and enforce the principle of least privilege by limiting user accounts to only those permissions necessary for operations. Monitor web console and database logs for suspicious SQL injection patterns. Organizations running EPM 2022 or earlier should prioritize upgrading to a supported and patched release.

Community reactions

The vulnerability was covered by cybersecurity news outlets including CyberSecurityNews and HealSecurity as part of broader Ivanti May 2026 patch coverage (CyberSecurityNews). The Belgian Centre for Cybersecurity (CCB) issued a warning advisory regarding Ivanti's May 2026 security updates. Community aggregators including Vulners, VulDB, and CVEFeed indexed the vulnerability shortly after disclosure, and Qualys published detection guidance as part of its May 2026 application security detections summary. No notable researcher commentary or significant social media debate has been identified beyond routine disclosure coverage.

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8111HIGH8.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-8110HIGH7.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1603HIGH7.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
YesNoFeb 10, 2026
CVE-2026-8109MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1602MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management