ZDI-26-079: Ivanti Endpoint Manager ROI SQL Injection Remote Code Execution Vulnerability
Published Feb 12, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Endpoint Manager. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-1602.
Affected Software
1 affected component
Ivanti Endpoint Manager
Event History
Feb 12, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-079?
The severity of ZDI-26-079 is rated at 7.2 according to the CVSS.
2
What software is affected by ZDI-26-079?
ZDI-26-079 affects Ivanti Endpoint Manager installations.
3
How do I fix ZDI-26-079?
To remediate ZDI-26-079, you should update your Ivanti Endpoint Manager to the latest version provided by Ivanti.
4
Is authentication required to exploit ZDI-26-079?
Yes, authentication is required to exploit the ZDI-26-079 vulnerability.
5
What type of vulnerability is ZDI-26-079?
ZDI-26-079 is a SQL injection vulnerability that allows remote code execution.