SB2026081132 - Multiple vulnerabilities in Ivanti Endpoint Manager (EPM)



SB2026081132 - Multiple vulnerabilities in Ivanti Endpoint Manager (EPM)

Published: August 11, 2026

Security Bulletin ID SB2026081132
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Out-of-bounds read (CVE-ID: CVE-2026-18125)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in the agent when handling network input. A remote attacker can send crafted input to crash an agent service to cause a denial of service.


2) External Control of File Name or Path (CVE-ID: CVE-2026-18127)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to overwrite data in an S3 bucket configured for session recording storage.

The vulnerability exists due to external control of a filename in the core when handling session recording storage filenames. A remote user can control a filename to gain full write control over an S3 bucket configured for session recording storage to overwrite data in an S3 bucket configured for session recording storage.

The issue affects configurations that use an S3 bucket for session recording storage.


3) Improper Certificate Validation (CVE-ID: CVE-2026-18129)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper certificate validation in the core when establishing external SQL connections. A remote attacker can perform a man-in-the-middle attack to leak credentials for external SQL connections to disclose sensitive information.

Exploitation requires a man-in-the-middle position.


Remediation

Install update from vendor's website.