An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.
| Vendor | Product | Versions |
|---|---|---|
| ivanti | neurons for itsm | 2026.1 before 2026.1 patch 9, 2026.2 before 2026.2 patch 1, 2025.2 before 2025.2 Patch 1, 2025.3 before 2025.3 Patch 1, 2025.4 before 2025.4 Patch 1 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| ivanti | neurons for itsm | cert_advisory | 90% |
Updated affected versions and marked exploit availability and active exploitation status as true.
Updated severity from HIGH to CRITICAL and corrected exploit availability to false.
Initial creation