Description
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Published: 2026-09-08
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw in Ivanti Neurons for ITSM allows a remote authenticated attacker to execute arbitrary code on the server, exposing the system to full compromise. The vulnerability is recorded as CWE‑862 (Missing Authorization). The CVSS score of 9.9 indicates extremely high severity, reflecting a significant risk to confidentiality, integrity, and availability if exploited.

Affected Systems

The flaw affects Ivanti Neurons for ITSM deployments prior to version 2026.2. Any installation of the product before 2026.2 that processes remote authentication is vulnerable, irrespective of the operating system.

Risk and Exploitability

The vulnerability can be leveraged by any user who can authenticate to the ITSM server, making it a remote but authenticated attack. While EPSS data is not available and the CVE is not listed in the CISA KEV catalog, the combination of a high CVSS score and the availability of credentials gives the attacker a realistic chance to exploit the flaw. CVEs with similar characteristics have been frequently targeted in the wild, suggesting this vulnerability poses a significant threat to organizations using the affected product.

Generated by OpenCVE AI on September 8, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Ivanti Neurons for ITSM version 2026.2 or later to apply the vendor’s fix.
  • Revoke or limit use of remote administrative access on the affected server, enforcing strict authentication and authorization controls.
  • Implement network segmentation or firewall rules to restrict inbound connections to the ITSM server, reducing the attack surface.

Generated by OpenCVE AI on September 8, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Missing Authorization Leaks Remote Code Execution in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-08T15:19:26.513Z

Reserved: 2026-06-18T18:25:46.456Z

Link: CVE-2026-12647

cve-icon Vulnrichment

Updated: 2026-09-08T15:19:23.097Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:40.623

Modified: 2026-09-08T16:17:56.877

Link: CVE-2026-12647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T16:30:07Z

Weaknesses