Impact
The vulnerability is a missing authorization flaw that permits a remote attacker who has authenticated credentials to execute arbitrary code on the server. This flaw permits a full compromise of the affected system because the attacker can run any command with the privileges of the web application, potentially exposing confidential data, tampering with configurations, and disrupting availability.
Affected Systems
Ivanti Neurons for ITSM is affected; all releases prior to version 2026.2 are vulnerable. Only the Ivanti Neurons for ITSM product is listed, so other Ivanti services are not impacted as far as the CVE indicates.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, and although an EPSS score is not available, the lack of a KEV listing does not diminish the risk. The flaw requires that the attacker already be authenticated, meaning it is most likely exploited by users with privileged accounts. Once authenticated, the attacker can execute code at the system level, giving full control over the server.
OpenCVE Enrichment