Description
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Published: 2026-09-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A deserialization flaw in Ivanti Neurons for ITSM allows an attacker who is already authenticated to the system to execute arbitrary code. The vulnerability is caused by untrusted input being deserialized without proper validation, which is a classic insecure deserialization weakness. If exploited, the attacker could gain control of the application server, manipulate data, and potentially access or exfiltrate sensitive information.

Affected Systems

All installations of Ivanti Neurons for ITSM before version 2026.2 are affected. The vulnerability targets the server component that processes user data, and only clients that can authenticate to the system can trigger the flaw.

Risk and Exploitability

The CVSS score of 8.8 classifies this as High severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote authenticated attack using valid credentials. The attacker must first obtain legitimate access to the system, after which arbitrary code execution can be achieved, but the CVE description does not specify whether higher privileges are required.

Generated by OpenCVE AI on September 8, 2026 at 16:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade or patch Ivanti Neurons for ITSM to version 2026.2 or later, which removes the unsafe deserialization path.
  • Restrict authentication to trusted accounts and enforce strong password or MFA policies to reduce the risk of an attacker gaining credentials.
  • Apply network segmentation and firewall rules to limit external entities from reaching the Neurons for ITSM server, adding an extra barrier before any potential exploitation.

Generated by OpenCVE AI on September 8, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability Allowing Remote Code Execution in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Deserialization Vulnerability Allowing Remote Code Execution in Ivanti Neurons for ITSM
First Time appeared Ivanti
Ivanti neurons For Itsm
Vendors & Products Ivanti
Ivanti neurons For Itsm

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ivanti Neurons For Itsm
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-08T15:20:48.374Z

Reserved: 2026-06-18T18:25:47.315Z

Link: CVE-2026-12648

cve-icon Vulnrichment

Updated: 2026-09-08T15:20:45.800Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:40.733

Modified: 2026-09-08T16:17:57.487

Link: CVE-2026-12648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T16:30:07Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data