CVE Vulnerabilities

CVE-2026-1603

Authentication Bypass Using an Alternate Path or Channel

Published: Feb 10, 2026 | Modified: Feb 12, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Affected Software

NameVendorStart VersionEnd Version
Endpoint_managerIvanti*2024 (excluding)
Endpoint_managerIvanti2024 (including)2024 (including)
Endpoint_managerIvanti2024-su1 (including)2024-su1 (including)
Endpoint_managerIvanti2024-su2 (including)2024-su2 (including)
Endpoint_managerIvanti2024-su3 (including)2024-su3 (including)
Endpoint_managerIvanti2024-su3_security_release_1 (including)2024-su3_security_release_1 (including)
Endpoint_managerIvanti2024-su4 (including)2024-su4 (including)
Endpoint_managerIvanti2024-su4_sr1 (including)2024-su4_sr1 (including)

Potential Mitigations

References