CVE-2026-12646

9.9

Ivanti · Ivanti Neurons for ITSM

A missing authorization vulnerability in Ivanti Neurons for ITSM allows a remote authenticated attacker to achieve arbitrary code execution on the server.

Executive summary

Ivanti Neurons for ITSM contains a critical missing authorization flaw that permits authenticated attackers to execute arbitrary code on the underlying server.

Vulnerability

This vulnerability is caused by a missing authorization check, identified as CWE-862, which allows an authenticated user to perform unauthorized actions. By exploiting this flaw, a remote attacker with low-level privileges can achieve remote code execution on the host server.

Business impact

The ability for an authenticated user to execute arbitrary code represents a total loss of system integrity and confidentiality. Given the CVSS score of 9.9, this vulnerability carries a critical severity rating, as it could allow an attacker to move laterally within the network or compromise sensitive internal data stored within the ITSM platform.

Remediation

Immediate Action: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later as specified in the official Ivanti security advisory.

Proactive Monitoring: Review system and application logs for suspicious process execution patterns or unauthorized attempts to access administrative functions.

Compensating Controls: Ensure that access to the ITSM interface is restricted to authorized personnel via secure VPN or zero-trust access controls, and utilize a Web Application Firewall to monitor for anomalous HTTP requests.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a severe risk due to the potential for arbitrary code execution. Organizations should prioritize updating to version 2026.2 immediately to neutralize this threat. If patching is not immediately feasible, restrict access to the application to the smallest possible user group to mitigate the risk of exploitation by compromised accounts.

More Ivanti CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources