CVE-2026-12645

9.9

Ivanti · Neurons for ITSM

A missing authorization flaw in Ivanti Neurons for ITSM allows a remote authenticated attacker to achieve remote code execution on the underlying server.

Executive summary

A critical missing authorization vulnerability in Ivanti Neurons for ITSM allows authenticated attackers to execute arbitrary code, posing a severe risk to server integrity and data confidentiality.

Vulnerability

The application fails to properly perform authorization checks (CWE-862), allowing an authenticated user to perform unauthorized actions. This flaw specifically enables remote code execution by an attacker who has already established a valid session with the system.

Business impact

The ability for an authenticated attacker to execute arbitrary code on the server represents a total compromise of the application environment. Given the high CVSS score of 9.9, this vulnerability could lead to complete data exfiltration, service disruption, and unauthorized lateral movement within the network, resulting in significant operational and reputational damage.

Remediation

Immediate Action: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later immediately to apply the necessary authorization controls.

Proactive Monitoring: Review web server and application access logs for unusual command execution patterns or unauthorized requests originating from low-privilege user accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious payloads and restrict access to administrative endpoints, although these are temporary measures and not a substitute for patching.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention from IT and security teams. Administrators should prioritize the update to version 2026.2 to eliminate the underlying authorization flaw. Given the potential for complete system compromise, organizations should treat this update with the highest urgency to ensure the security and stability of the Ivanti Neurons environment.

More Ivanti CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources