Description
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Published: 2026-09-08
Score: 9.9 Critical
EPSS: 1.2% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A missing authorization flaw in Ivanti Neurons for ITSM allows a remote authenticated attacker to execute arbitrary code on the server, exposing the system to full compromise. The vulnerability is recorded as CWE‑862 (Missing Authorization). The CVSS score of 9.9 indicates extremely high severity, reflecting a significant risk to confidentiality, integrity, and availability if exploited.

Affected Systems

The flaw affects Ivanti Neurons for ITSM deployments prior to version 2026.2. Any installation of the product before 2026.2 that processes remote authentication is vulnerable, irrespective of the operating system.

Risk and Exploitability

The vulnerability can be leveraged by any user who can authenticate to the ITSM server, making it a remote but authenticated attack. The EPSS score is 1%, indicating a low but non‑zero probability of exploitation. While the CVE is not listed in the CISA KEV catalog, the combination of a high CVSS score and the availability of credentials gives the attacker a realistic chance to exploit the flaw. CVEs with similar characteristics have been frequently targeted in the wild, suggesting this vulnerability poses a significant threat to organizations using the affected product.

Generated by OpenCVE AI on September 10, 2026 at 03:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Ivanti Neurons for ITSM version 2026.2 or later to apply the vendor’s fix.
  • Revoke or limit use of remote administrative access on the affected server, enforcing strict authentication and authorization controls.
  • Implement network segmentation or firewall rules to restrict inbound connections to the ITSM server, reducing the attack surface.

Generated by OpenCVE AI on September 10, 2026 at 03:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ivanti:neurons_for_itsm:2025.2:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2025.3:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2025.4:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2026.1:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:neurons_for_itsm:2026.2:*:*:*:*:*:*:*

Thu, 10 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Title Missing Authorization Leaks Remote Code Execution in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti neurons For Itsm
Vendors & Products Ivanti
Ivanti neurons For Itsm

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization Leaks Remote Code Execution in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ivanti Neurons For Itsm
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-09T04:26:50.275Z

Reserved: 2026-06-18T18:25:46.456Z

Link: CVE-2026-12647

cve-icon Vulnrichment

Updated: 2026-09-08T15:19:23.097Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T15:18:40.623

Modified: 2026-09-18T18:14:02.137

Link: CVE-2026-12647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:15:16Z

Weaknesses