CVE-2026-9614
Neurons for ITSM: Improper Access Control (CVE-2026-9614)
highEPSS 1.2%
Affected
- Ivanti/Neurons for ITSM
On-Premises 2025.4 Patch 1..* - Ivanti/Neurons for ITSM
On-Premises 2025.3 Patch 1..* - Ivanti/Neurons for ITSM
On-Premises 2025.2 Patch 1..* - Ivanti/Neurons for ITSM
Cloud 2026.1 patch 9..* - Ivanti/Neurons for ITSM
Cloud 2026.2 patch 1..*
Description
An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
IvantiNeurons for ITSM
Cloud 2026.1 patch 9Cloud 2026.2 patch 1On-Premises 2025.2 Patch 1On-Premises 2025.3 Patch 1On-Premises 2025.4 Patch 1Metrics
Show all metrics
Severity
high
99.81
no public PoC known
8.8
Published
2026-06-01 19:16 UTC
CWE-284
Weakness classes (CWE)
CWE-284Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
cwe.mitre.org →