Description
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Published: 2026-09-08
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that permits a remote attacker who has authenticated credentials to execute arbitrary code on the server. This flaw permits a full compromise of the affected system because the attacker can run any command with the privileges of the web application, potentially exposing confidential data, tampering with configurations, and disrupting availability.

Affected Systems

Ivanti Neurons for ITSM is affected; all releases prior to version 2026.2 are vulnerable. Only the Ivanti Neurons for ITSM product is listed, so other Ivanti services are not impacted as far as the CVE indicates.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity, and although an EPSS score is not available, the lack of a KEV listing does not diminish the risk. The flaw requires that the attacker already be authenticated, meaning it is most likely exploited by users with privileged accounts. Once authenticated, the attacker can execute code at the system level, giving full control over the server.

Generated by OpenCVE AI on September 8, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Ivanti Neurons for ITSM update that brings the product to version 2026.2 or later.
  • If an immediate update is not feasible, enforce strict role‑based access controls and ensure that only trusted administrators have the privileges needed to log into the system.
  • Implement network segmentation so that the Neurons server is isolated from critical assets and monitor for anomalous activity such as unexpected privileged process execution.

Generated by OpenCVE AI on September 8, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization Enables Remote Code Execution in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti neurons For Itsm
Vendors & Products Ivanti
Ivanti neurons For Itsm

Tue, 08 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization Enables Remote Code Execution in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ivanti Neurons For Itsm
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-08T15:20:14.543Z

Reserved: 2026-06-18T18:25:44.634Z

Link: CVE-2026-12645

cve-icon Vulnrichment

Updated: 2026-09-08T15:20:12.134Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:40.380

Modified: 2026-09-08T16:17:54.143

Link: CVE-2026-12645

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T16:30:07Z

Weaknesses