ZDI-CAN-26885: ZDI-26-080: Ivanti Endpoint Manager AuthHelper Authentication Bypass Vulnerability
Published Feb 12, 2026
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Endpoint Manager. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.6. The following CVEs are assigned: CVE-2026-1603.
Affected Software
1 affected component
Ivanti Endpoint Manager
Event History
Feb 12, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-26885?
ZDI-CAN-26885 is considered a high-severity vulnerability due to its impact on authentication bypass.
2
How do I fix ZDI-CAN-26885?
To fix ZDI-CAN-26885, update to the latest version of Ivanti Endpoint Manager as per the vendor's advisory.
3
What types of attacks can ZDI-CAN-26885 enable?
ZDI-CAN-26885 can enable remote attackers to gain unauthorized access and control over affected systems.
4
Is authentication required to exploit ZDI-CAN-26885?
No, authentication is not required to exploit ZDI-CAN-26885, making it highly exploitable.
5
Which software is affected by ZDI-CAN-26885?
ZDI-CAN-26885 affects Ivanti Endpoint Manager installations.