Improper Certificate Validation in Endpoint Manager - CVE-2026-18129
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper certificate validation in the core when establishing external SQL connections. A remote attacker can perform a man-in-the-middle attack to leak credentials for external SQL connections to disclose sensitive information.
Exploitation requires a man-in-the-middle position.