All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-18129
HIGHpublished 2026-08-11 15:17 UTC · 1 day ago · modified 2026-08-12 05:17 UTC
8.1
CVSS / 10
// description
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
// weaknesses (CWE)
- CWE-295