Junglewise Threat Intelligence

CVE-2026-12647: Ivanti Neurons for ITSM missing authorization remote code execution

CVE-2026-12647 · Severity: critical · CVSS 9.9 · Published 2026-09-08

Technologies: Ivanti Neurons for ITSM. Vendors: Ivanti.

Executive brief

Ivanti Neurons for ITSM is an IT service management platform used by organizations to manage incidents, changes, and other IT operations. A missing authorization flaw allows authenticated attackers to execute arbitrary code on the server, potentially compromising the entire ITSM infrastructure, causing service outages, and enabling data theft or lateral movement within the network.

Technical details

This vulnerability is a missing authorization (CWE-862) issue in Ivanti Neurons for ITSM versions before 2026.2. An authenticated remote attacker can exploit insufficient access controls to execute arbitrary code on the affected server. The attack requires valid credentials but does not require additional user interaction. Successful exploitation grants an attacker full server-level code execution capabilities. Ivanti has released patches in version 2026.2 and later to address this flaw.

Affected products

  • Ivanti Neurons for ITSM before 2026.2

Timeline

  • 2026-09-08: disclosed

References

Related threats