← All Advisories

Ivanti Virtual Traffic Manager OS Command Injection Requires Authenticated Admin Access to Reach Remote Code Execution

Last refreshed2026-09-29

Status: UPDATED  |  Advisory ID: CVE-2026-8051

Key Details

CVECVE-2026-8051
CVSS Score / Version7.2 (High) / CVSS v3.1
Updated2026-06-17
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsIvanti virtual_traffic_manager
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Ivantivirtual_traffic_manager
SubsystemsGeneral OT
SectorsMultiple

What to Know

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

What to Do

Monitor Ivanti's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-8051
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-8051
Vendor advisoryhttps://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2026-8051?language=en_US