ZDI-26-308: Ivanti Endpoint Manager RemoteControlAuth Exposed Dangerous Method Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Ivanti Endpoint Manager. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-8109.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-308?
The severity of ZDI-26-308 is high due to its potential for unauthorized disclosure of sensitive information.
How do I fix ZDI-26-308?
To fix ZDI-26-308, apply the latest patches provided by Ivanti for Endpoint Manager.
What types of systems are impacted by ZDI-26-308?
ZDI-26-308 affects installations of Ivanti Endpoint Manager that have not been updated to resolve this vulnerability.
What information can be disclosed due to ZDI-26-308?
ZDI-26-308 may allow attackers to access sensitive information that could include user credentials and other confidential data.
Is authentication required to exploit ZDI-26-308?
Yes, authentication is required to exploit ZDI-26-308, which limits the potential attackers to authenticated users.