← Back

Incapptic Connect

incapptic_connect

Vendor: Ivanti • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
1Incapptic Connect
Jun 17, 2026
Apr 11, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.
1Ivanti
1Incapptic Connect
Jun 17, 2026
Apr 11, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An authenticated high privileged user can perform a stored XSS attack due to incorrect output encoding in Incapptic connect and affects all current versions.
1Ivanti
1Incapptic Connect
Jun 17, 2026
Mar 4, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38...Show more
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.Show less