Executive brief
Ivanti Neurons for ITSM is a platform used by organizations to manage IT service requests, assets, and workflows. A security vulnerability in this system allows a user who is already logged into the platform to bypass security checks and gain full administrative control. This could lead to unauthorized access to sensitive corporate data, modification of IT workflows, or complete disruption of service management operations.
Technical details
An Improper Access Control vulnerability (CWE-284) exists in Ivanti Neurons for ITSM affecting both cloud and on-premises deployments. The flaw allows a remote attacker with low-privileged authenticated access to bypass intended authorization constraints and escalate their privileges to administrative levels. The attack is network-reachable and requires no user interaction. Successful exploitation grants the attacker full control over the ITSM environment, including the ability to access, modify, or delete sensitive data and configurations. Ivanti has released a security advisory to address this issue.
Affected products
- Ivanti Neurons for ITSM Cloud and On-Premises versions
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory