CVE-2026-1603: Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
Other sources
Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Manager (EPM)to a version that resolves this vulnerability.Fixed in 2024 SU5 - Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of Ivanti Endpoint Manager (EPM) if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1603?
The severity of CVE-2026-1603 is considered high due to its potential for authentication bypass and remote exploitation.
How do I fix CVE-2026-1603?
To fix CVE-2026-1603, update Ivanti Endpoint Manager to version 2024 SU5 or later.
What data is vulnerable in CVE-2026-1603?
CVE-2026-1603 allows attackers to leak specific stored credential data from Ivanti Endpoint Manager.
Who is affected by CVE-2026-1603?
Organizations using Ivanti Endpoint Manager versions prior to 2024 SU5 are affected by CVE-2026-1603.
Can CVE-2026-1603 be exploited remotely?
Yes, CVE-2026-1603 can be exploited by remote unauthenticated attackers.