AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18127

HIGH · CVSS 7.7 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Ivanti Endpoint Manager versions prior to 2024 SU7 are vulnerable to an external control of a filename, enabling remote authenticated attackers to gain full write access to S3 buckets used for session recording storage. This vulnerability poses a significant risk as it could lead to unauthorized data manipulation or exposure. Organizations using affected versions should prioritize patching to mitigate potential data breaches and maintain security integrity.

CVE
CVE-2026-18127
Severity
HIGH
CVSS
7.7
EPSS
0.39%
Ivanti

Original NVD Description

External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.