CVE-2026-18127 is a high-severity external control of filename vulnerability in the Core component of Ivanti Endpoint Manager prior to version 2024 SU7. The flaw allows a remote authenticated attacker to supply a crafted filename that is insufficiently constrained when interacting with session recording storage, resulting in attacker-controlled write operations against an Amazon S3 bucket configured for session recording storage. The issue affects deployments that use S3-backed storage for session recordings and can enable unauthorized manipulation of objects stored in that bucket.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity Ivanti Endpoint Manager vulnerability that allows attackers to gain full write access to S3 buckets used for session recording storage by supplying a specially crafted filename.
A high-severity input validation vulnerability in Ivanti Endpoint Manager that allows remote attackers to control filenames and could let an authenticated attacker gain full write control over an S3 bucket used for session recording storage.
High-severity vulnerability in Ivanti Endpoint Manager (EPM) that could allow access to sensitive information, data manipulation, and/or impact service availability on affected systems.
An external control of filename vulnerability in Ivanti Endpoint Manager Core that allows an authenticated remote attacker to gain write access to an Amazon S3 bucket used for session recording storage.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.