CVE-2026-18127: High severity vulnerability
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Manager (Core)to a version that resolves this vulnerability.Fixed in 2024 SU7 - Compensating control
Ensure S3 bucket(s) used for session recording storage are not writable by external/compromised identities; restrict write access to only the specific, expected session-recording service role/account.