# Ivanti Connect Secure SAML SSRF, chained to auth bypass

Source: https://startwithidentity.com/cves/cve-2024-21893/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

The [SAML](https://startwithidentity.com/glossary/saml/) stack on Ivanti Connect Secure (9.x, 22.x) and Policy Secure would fetch attacker-controlled URLs (SSRF). After the January 2024 patches for [CVE-2023-46805](https://startwithidentity.com/cves/cve-2023-46805/) (auth bypass) and CVE-2024-21887 (command injection), attackers used this SAML SSRF as the leftover door. CISA added it to KEV. watchTowr and Rapid7 published the chain.

## Why it matters

VPN concentrators are identity enforcement points. When the SAML ACS can be turned into an SSRF, "we federated login" becomes "the IdP conversation is an attack primitive." This is why FortiCloud SSO and Ivanti keep landing on the same page of this catalog.

## What to do

- Patch ICS/IPS for CVE-2024-21893 even if you already took the 46805 / 21887 builds.
- If the box was internet-facing in January–February 2024, assume compromise. Rebuild, do not just patch.
- Hunt for unexpected XML from the SAML ACS, new local admins, and outbound connections from the appliance.
- Disable SAML on the appliance if you do not need it. A VPN that does local auth is better than a VPN whose ACS is an SSRF.

## After you patch

Edge appliances sit outside the estate and hold credentials into it, which is why this class keeps producing multi-victim campaigns.

- **Revoke all sessions on the appliance**, then rotate the directory or [LDAP](https://startwithidentity.com/glossary/federation/) service account it uses for authentication.
- **Rotate certificates and any stored integration credentials**, since configuration stores on these devices are a routine post-exploitation target.
- **Hunt for authenticated sessions with no matching interactive login**, and for logins from ASNs that had never appeared before the disclosure date.
- **Check downstream**: anything the appliance could reach or authenticate to is in scope, including [SSO](https://startwithidentity.com/glossary/sso/)-connected applications.

## Sources

- [NVD: CVE-2024-21893](https://nvd.nist.gov/vuln/detail/CVE-2024-21893)
- CISA KEV
- Rapid7 / watchTowr analyses of the Ivanti SAML SSRF chain
