Junglewise Threat Intelligence

CVE-2026-12646: Ivanti Neurons for ITSM missing authorization code execution

CVE-2026-12646 · Severity: critical · CVSS 9.9 · Published 2026-09-08

Technologies: Ivanti Neurons for ITSM. Vendors: Ivanti.

Executive brief

Ivanti Neurons for ITSM is a service management platform used to handle IT incidents, requests, and change management across organizations. A missing authorization vulnerability allows authenticated users to execute arbitrary code on the server, potentially compromising the entire platform and the sensitive IT data it manages. This could enable an attacker to take control of IT operations, expose confidential business and customer information, or disrupt critical services.

Technical details

This is a missing authorization vulnerability (CWE-862) in Ivanti Neurons for ITSM versions before 2026.2. The vulnerability requires authentication but fails to properly validate that the authenticated user is authorized to perform sensitive operations, specifically arbitrary code execution. The flaw exists in the application's access control logic, allowing a remote authenticated attacker to execute arbitrary code on the server. This vulnerability has a CVSS score of 9.9 (critical), indicating severe impact. No evidence of active exploitation in the wild has been reported, but patched versions are available.

Affected products

  • Ivanti Neurons for ITSM before 2026.2

Timeline

  • 2026-09-08: disclosed

References

Related threats