LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-8111 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: May 12, 2026

Ivanti Endpoint Manager - SQL Injection

Published: May 12, 2026Updated: May 12, 2026Remote Exploitable

Overview

Ivanti Endpoint Manager < 2024 SU6 contains a SQL injection caused by improper sanitization in the web console, letting remote authenticated attackers achieve remote code execution.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Remote authenticated attackers can execute arbitrary code, potentially compromising the entire system.

Mitigation

Update to version 2024 SU6 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
May 12, 2026

🟠 CVE-2026-8111 - High (8.8) SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-8111/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
May 12, 2026

🟠 CVE-2026-8111 - High (8.8) SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-8111/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-8111
Severity
High
CVSS Score
8.8
Type
sql_injection
Status
confirmed
EPSS
0.0%
Social Posts
2

CWE

  • CWE-89

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days