Impact
A deserialization flaw in Ivanti Neurons for ITSM allows an attacker who is already authenticated to the system to execute arbitrary code. The vulnerability is caused by untrusted input being deserialized without proper validation, which is a classic insecure deserialization weakness. If exploited, the attacker could gain control of the application server, manipulate data, and potentially access or exfiltrate sensitive information.
Affected Systems
All installations of Ivanti Neurons for ITSM before version 2026.2 are affected. The vulnerability targets the server component that processes user data, and only clients that can authenticate to the system can trigger the flaw.
Risk and Exploitability
The CVSS score of 8.8 classifies this as High severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote authenticated attack using valid credentials. The attacker must first obtain legitimate access to the system, after which arbitrary code execution can be achieved, but the CVE description does not specify whether higher privileges are required.
OpenCVE Enrichment