What is CVE-2026-18129?
CVE-2026-18129 is a cleartext transmission of sensitive information vulnerability in the Core of Ivanti Endpoint Manager before version 2024 SU7. It allows a remote, unauthenticated attacker in a Man-in-the-Middle (MITM) position to intercept and leak credentials for external SQL connections. Affected systems should be urgently updated to the patched version.
Azərbaycanca: CVE-2026-18129, Ivanti Endpoint Manager-in Core komponentində həssas məlumatların şifrələnməmiş ötürülməsi zəifliyidir. Bu, 2024 SU7 versiyasından əvvəlki versiyalara təsir edir və şəbəkə arasında olan (MITM) uzaq autentifikasiya olunmamış hücumçuya xarici SQL bağlantıları üçün etimadnamələri əldə etməyə imkan verir. Təsirə məruz qalan sistemlər dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: shared vendor: Ivanti
FAQ1
Which Ivanti product is affected by CVE-2026-18129?
This vulnerability affects the Core component of Ivanti Endpoint Manager.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.