Description
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Published: 2026-08-11
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Ivanti Endpoint Manager allows an attacker who can authenticate to the system to specify an arbitrary filename for session recording files. This external control of the filename enables the attacker to write files directly into an S3 bucket used for storing session recordings. The result is full write authority over that bucket, allowing the attacker to overwrite, delete, or tamper with recorded data, potentially compromising data integrity, confidentiality, and availability. The vulnerability is a classic example of Improper Restriction on Use of Identifier (CWE‑73) that permits remote control of a file path. Because the flaw requires remote authentication, an attacker must first compromise or use valid credentials to the Endpoint Manager. Once authenticated, the attacker can immediately exploit the file‑name control to modify the storage bucket. The CVSS score of 7.7 denotes high severity; the EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog, but the potential for data loss or compromise remains high.

Affected Systems

Ivanti Endpoint Manager prior to release 2024 SU7 is affected. The core component that processes session recordings configured to use Amazon S3 storage is vulnerable.

Risk and Exploitability

This vulnerability requires the attacker to be authenticated to Endpoint Manager. Once authenticated, the attacker can supply an arbitrary filename during session recording creation, which the system then forwards to the configured S3 bucket. This gives the attacker full write authority over that bucket, allowing overwrites, deletions, or insertion of malicious objects. The CVSS score of 7.7 indicates high severity, while the EPSS score is currently unavailable and the vulnerability is not listed in the CISA KEV catalog. Despite these metrics, the potential impact on confidentiality, integrity, and availability of recorded session data is significant.

Generated by OpenCVE AI on August 11, 2026 at 23:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Ivanti security update that addresses the filename control issue (v2024 SU7 or later).
  • Restrict the IAM policy of the S3 bucket used for session recordings to read‑only, removing write permissions for all users, including those authenticated to Endpoint Manager.
  • Enable CloudTrail logging for the S3 bucket and set up alerts for object creation or modification events to detect unauthorized writes.

Generated by OpenCVE AI on August 11, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Remote Write Control to S3 Bucket via External Filename in Ivanti Endpoint Manager
First Time appeared Ivanti
Ivanti endpoint Manager
Vendors & Products Ivanti
Ivanti endpoint Manager

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Ivanti Endpoint Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-08-11T14:49:59.092Z

Reserved: 2026-07-28T18:10:07.383Z

Link: CVE-2026-18127

cve-icon Vulnrichment

Updated: 2026-08-11T14:49:55.260Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T15:17:28.193

Modified: 2026-08-31T19:27:23.020

Link: CVE-2026-18127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T23:30:06Z

Weaknesses
  • CWE-73

    External Control of File Name or Path