Description
A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Published: 2026-09-08
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A deserialization flaw in Ivanti Neurons for ITSM allows a remote authenticated attacker to execute arbitrary code on the server. The vulnerability stems from processing untrusted data without proper validation, which satisfies CWE‑502. If exploited, the attacker can gain full control over the application server and any underlying operating system resources, leading to complete compromise of the ITSM infrastructure.

Affected Systems

All installations of Ivanti Neurons for ITSM released before version 2026.2 are impacted. This includes any deployment of the product where users have authenticated access to the service.

Risk and Exploitability

The CVSS score is 9.9, indicating a critical severity. Because EPSS data is unavailable and the vulnerability is not listed in CISA KEV, the precise exploitation probability cannot be quantified from the public data. The attack requires an authenticated session, so privilege escalation to an account with sufficient rights is necessary, but the impact is local to the server where the service runs. If successful, the attacker can achieve full code execution and compromise confidentiality, integrity, and availability of the system.

Generated by OpenCVE AI on September 8, 2026 at 16:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Ivanti Neurons for ITSM v2026.2 or later to eliminate the vulnerable deserialization path.
  • If an upgrade is not immediately possible, restrict external network access to the Neurons for ITSM server and enforce least‑privilege role‑based access controls.
  • Apply any interim security patches released by Ivanti and verify that all deserialization APIs handling untrusted data are disabled or removed.

Generated by OpenCVE AI on September 8, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Deserialization in Ivanti Neurons for ITSM

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti neurons For Itsm
Vendors & Products Ivanti
Ivanti neurons For Itsm

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ivanti Neurons For Itsm
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-09-08T15:21:09.129Z

Reserved: 2026-06-18T18:25:49.156Z

Link: CVE-2026-12650

cve-icon Vulnrichment

Updated: 2026-09-08T15:21:02.605Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:40.850

Modified: 2026-09-08T16:17:58.087

Link: CVE-2026-12650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T16:30:07Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data