CVE-2025-8296: SQL Injection
Published Aug 12, 2025
·Updated
SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution
Affected Software
2 affected components
Ivanti Avalanche<6.4.8.8008
Ivanti Avalanche<6.4.8.8008
Event History
Aug 12, 2025
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
May 23, 57600
Event
via FIRST·09:47 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-8296?
CVE-2025-8296 is rated as critical due to potential remote code execution through SQL injection.
2
How do I fix CVE-2025-8296?
To mitigate CVE-2025-8296, upgrade Ivanti Avalanche to version 6.4.8.8009 or later.
3
Who is affected by CVE-2025-8296?
CVE-2025-8296 affects users of Ivanti Avalanche versions prior to 6.4.8.8008 who have admin privileges.
4
What type of vulnerability is CVE-2025-8296?
CVE-2025-8296 is an SQL injection vulnerability that can allow unauthorized SQL queries.
5
Can CVE-2025-8296 lead to data compromise?
Yes, CVE-2025-8296 can potentially lead to a complete compromise of the application database through SQL injection.