CVE-2026-1602: SQL Injection
Published Feb 10, 2026
·Updated
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Affected Software
9 affected components
Ivanti Endpoint Manager<2024 SU5
Ivanti Endpoint Manager<2024
Ivanti Endpoint Manager=2024
Ivanti Endpoint Manager=2024-su1
Ivanti Endpoint Manager=2024-su2
Ivanti Endpoint Manager=2024-su3
Ivanti Endpoint Manager=2024-su3_security_release_1
Ivanti Endpoint Manager=2024-su4
Ivanti Endpoint Manager=2024-su4_sr1
Event History
Feb 10, 2026
CVE Published
via MITRE·03:07 PM
Data Sourced
via MITRE·03:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-1602?
CVE-2026-1602 is considered a critical vulnerability due to the potential for unauthorized data access.
2
How do I fix CVE-2026-1602?
To fix CVE-2026-1602, upgrade Ivanti Endpoint Manager to version 2024 SU5 or later.
3
What impact does CVE-2026-1602 have on my system?
CVE-2026-1602 allows a remote authenticated attacker to read arbitrary data from the database, which can lead to data breaches.
4
Who is affected by CVE-2026-1602?
CVE-2026-1602 affects all versions of Ivanti Endpoint Manager prior to 2024 SU5.
5
Is authentication required to exploit CVE-2026-1602?
Yes, CVE-2026-1602 requires the attacker to be remotely authenticated to exploit the SQL injection vulnerability.