CVE-2026-18127

External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 15:17

Updated : 2026-08-31 19:27


NVD link : CVE-2026-18127

Mitre link : CVE-2026-18127

CVE.ORG link : CVE-2026-18127


JSON object : View

Products Affected

No product.

CWE
CWE-73

External Control of File Name or Path