Junglewise Threat Intelligence

CVE-2026-14902: Ivanti Xtraction open redirect

CVE-2026-14902 · Severity: medium · CVSS 4 · Published 2026-07-14

Technologies: Ivanti Xtraction. Vendors: Ivanti.

Executive brief

Ivanti Xtraction is a self-service dashboarding and reporting solution used to visualize data from various IT management systems. A security flaw in this product allows attackers to redirect users to malicious external websites. This could be used in phishing campaigns to trick employees into providing credentials or downloading malware by making a malicious link appear to originate from a trusted corporate reporting tool.

Technical details

An open redirect vulnerability (CWE-601) exists in Ivanti Xtraction prior to version 2026.2.1. The application fails to properly validate user-supplied input used in redirection targets, allowing a remote, unauthenticated attacker to craft a URL that redirects a victim to an untrusted external site. While the CVSS vector indicates high complexity (AC:H), the flaw can be exploited by enticing a user to click a specially crafted link. This vulnerability is resolved in Ivanti Xtraction version 2026.2.1.

Affected products

  • Ivanti Xtraction before 2026.2.1

Timeline

  • 2026-07-14: advisory: Initial advisory published by Ivanti and NVD.
  • 2026-07-14: patched: Vulnerability fixed in version 2026.2.1.

References

Related threats