CVE-2026-8111: SQL Injection
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Manager (web console)to a version that resolves this vulnerability.Fixed in 2024 SU6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8111?
CVE-2026-8111 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2026-8111?
To fix CVE-2026-8111, upgrade your Ivanti Endpoint Manager to version 2024 SU6 or later.
What types of attacks can CVE-2026-8111 facilitate?
CVE-2026-8111 can facilitate SQL injection attacks that lead to remote code execution.
Who is affected by CVE-2026-8111?
Organizations using Ivanti Endpoint Manager versions prior to 2024 SU6 are affected by CVE-2026-8111.
Are both authenticated and unauthenticated users vulnerable to CVE-2026-8111?
Only remote authenticated attackers can exploit CVE-2026-8111 to execute remote code.