Executive brief
Ivanti Neurons for ITSM is an IT service management platform used by organizations to manage IT infrastructure and support requests. A missing authorization flaw allows authenticated attackers to execute arbitrary code on the server, compromising the confidentiality, integrity, and availability of the entire platform and potentially exposing sensitive customer and operational data.
Technical details
The vulnerability is a missing authorization check in Ivanti Neurons for ITSM versions before 2026.2. An authenticated attacker can bypass authorization controls to execute arbitrary code on the server via an unspecified vector. The attack requires prior authentication but no additional privileges or user interaction. Successful exploitation grants remote code execution (RCE) on the affected server, allowing full system compromise. Ivanti has released patches in version 2026.2 and later.
Affected products
- Ivanti Neurons for ITSM before 2026.2
Timeline
- 2026-09-08: disclosed