Impact
A missing authorization flaw in Ivanti Neurons for ITSM allows a remote authenticated attacker to execute arbitrary code on the server, exposing the system to full compromise. The vulnerability is recorded as CWE‑862 (Missing Authorization). The CVSS score of 9.9 indicates extremely high severity, reflecting a significant risk to confidentiality, integrity, and availability if exploited.
Affected Systems
The flaw affects Ivanti Neurons for ITSM deployments prior to version 2026.2. Any installation of the product before 2026.2 that processes remote authentication is vulnerable, irrespective of the operating system.
Risk and Exploitability
The vulnerability can be leveraged by any user who can authenticate to the ITSM server, making it a remote but authenticated attack. While EPSS data is not available and the CVE is not listed in the CISA KEV catalog, the combination of a high CVSS score and the availability of credentials gives the attacker a realistic chance to exploit the flaw. CVEs with similar characteristics have been frequently targeted in the wild, suggesting this vulnerability poses a significant threat to organizations using the affected product.
OpenCVE Enrichment