Impact
A deserialization flaw in Ivanti Neurons for ITSM allows a remote authenticated attacker to execute arbitrary code on the server. The vulnerability stems from processing untrusted data without proper validation, which satisfies CWE‑502. If exploited, the attacker can gain full control over the application server and any underlying operating system resources, leading to complete compromise of the ITSM infrastructure.
Affected Systems
All installations of Ivanti Neurons for ITSM released before version 2026.2 are impacted. This includes any deployment of the product where users have authenticated access to the service.
Risk and Exploitability
The CVSS score is 9.9, indicating a critical severity. Because EPSS data is unavailable and the vulnerability is not listed in CISA KEV, the precise exploitation probability cannot be quantified from the public data. The attack requires an authenticated session, so privilege escalation to an account with sufficient rights is necessary, but the impact is local to the server where the service runs. If successful, the attacker can achieve full code execution and compromise confidentiality, integrity, and availability of the system.
OpenCVE Enrichment