Skip to content
COOEY

FAIL › dossier

Endpoint Manager (EPM)

PRODUCT

· dossier confidence 0%

Ivanti Endpoint Manager has a critically poor security track record, characterized by a series of high-severity, unauthenticated vulnerabilities including remote code execution and credential leakage. The company's security posture is fundamentally flawed, requiring immediate and rigorous remediation to meet defense-industrial-base compliance standards.

PROFILE
CategoryEndpoint Management SoftwareWhat they doIvanti Endpoint Manager (EPM) is an endpoint management solution that provides IT management, security, and compliance capabilities for organizations.
SECURITY POSTURE

The security posture is severely compromised by a pattern of high-severity, unauthenticated vulnerabilities across multiple years, indicating systemic issues in secure coding, patch management, and threat modeling.

Notable failures
  • CVE-2026-1603: Unauthenticated bypass of authentication and credential leakage
  • CVE-2024-29824: Unauthenticated SQL injection enabling arbitrary code execution
  • CVE-2024-13159: Unauthenticated path traversal enabling sensitive information leakage
Patterns: Repeated unauthenticated high-severity vulnerabilities (RCE, credential leakage, path traversal); Lack of effective patch management or secure development lifecycle (SDL) controls
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2026-03-09 CVE-2026-1603 high Ivanti Endpoint Manager allows remote unauthenticated attackers to bypass authentication and leak stored credentials via an alternate path.
2024-10-02 CVE-2024-29824 high Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network.
2025-03-10 CVE-2024-13159 high Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
2025-03-10 CVE-2024-13160 high Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
2025-03-10 CVE-2024-13161 high Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
DOSSIER SOURCES
Open questions: Ivanti's corporate headquarters location · Ivanti's founding year · Ivanti's current ownership structure
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-25 03:52:50.301244+00:00