CVE-2025-8296

HIGH

Ivanti Avalanche < 6.4.8.8008 - Authenticated SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution

Scores

CVSS v3 7.2
EPSS 0.0656
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
ivanti/avalanche < 6.4.8.8008
Published Aug 12, 2025
Tracked Since Feb 18, 2026