What is CVE-2026-18127?
This vulnerability in Ivanti Endpoint Manager core before version 2024 SU7 allows an attacker to gain full write control over an S3 bucket configured for session recording storage via external control of a filename. A remote authenticated attacker can exploit this to compromise the session recording bucket. Updating to version 2024 SU7 or later is strongly recommended.
Azərbaycanca: Bu boşluq İvanti Endpoint Manager-in 2024 SU7 versiyasından əvvəlki nüvəsində fayl adına xarici nəzarət imkanı yaradır. Uzaqdan autentifikasiya olunmuş hücumçuya S3 bucket üzərində tam yazma nəzarəti əldə etməyə imkan verir. Mümkün qədər tez 2024 SU7 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What kind of attacker can exploit CVE-2026-18127 in Ivanti Endpoint Manager?
A remote authenticated attacker can exploit this vulnerability.
What level of control can an attacker gain over the S3 bucket by exploiting CVE-2026-18127?
The attacker can gain full write control over the S3 bucket configured for session recording storage.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.