CVE-2026-9614

Neurons for ITSM: Improper Access Control (CVE-2026-9614)

Affected

  • Ivanti/Neurons for ITSM On-Premises 2025.4 Patch 1..*
  • Ivanti/Neurons for ITSM On-Premises 2025.3 Patch 1..*
  • Ivanti/Neurons for ITSM On-Premises 2025.2 Patch 1..*
  • Ivanti/Neurons for ITSM Cloud 2026.1 patch 9..*
  • Ivanti/Neurons for ITSM Cloud 2026.2 patch 1..*

Description

An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

IvantiNeurons for ITSM
Cloud 2026.1 patch 9Cloud 2026.2 patch 1On-Premises 2025.2 Patch 1On-Premises 2025.3 Patch 1On-Premises 2025.4 Patch 1

Metrics

8.8
Source: nvd-v3
67.6 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
high
no public PoC known
1.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-06-01 19:16 UTC
CWE-284

Weakness classes (CWE)

  • CWE-284Pillar

    Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    cwe.mitre.org →

References & sources

Linked advisories