Refine your search

4 vulnerabilities found for Neurons for ITSM (Cloud) by Ivanti

CERTFR-2026-AVI-0677
Vulnerability from certfr_avis

Une vulnérabilité a été découverte dans les produits Ivanti. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Impacted products
Vendor Product Description
Ivanti Neurons for ITSM (On-Premises) Neurons for ITSM (On-Premises) version 2025.3 antérieures à 2025.3 Patch 1
Ivanti Neurons for ITSM (Cloud) Neurons for ITSM (Cloud) version 2026.1 antérieures à 2026.1 patch 9
Ivanti Neurons for ITSM (On-Premises) Neurons for ITSM (On-Premises) version 2025.2 antérieures à 2025.2 Patch 1
Ivanti Neurons for ITSM (On-Premises) Neurons for ITSM (On-Premises) version 2025.4 antérieures à 2025.4 Patch 1
Ivanti Neurons for ITSM (Cloud) Neurons for ITSM (Cloud) version 2026.2 antérieures à 2026.2 patch 1

Show details on source website


{
  "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
  "affected_systems": [
    {
      "description": "Neurons for ITSM (On-Premises) version 2025.3 ant\u00e9rieures \u00e0 2025.3 Patch 1 ",
      "product": {
        "name": "Neurons for ITSM (On-Premises)",
        "vendor": {
          "name": "Ivanti",
          "scada": false
        }
      }
    },
    {
      "description": "Neurons for ITSM (Cloud) version 2026.1 ant\u00e9rieures \u00e0 2026.1 patch 9",
      "product": {
        "name": "Neurons for ITSM (Cloud)",
        "vendor": {
          "name": "Ivanti",
          "scada": false
        }
      }
    },
    {
      "description": "Neurons for ITSM (On-Premises) version 2025.2 ant\u00e9rieures \u00e0 2025.2 Patch 1 ",
      "product": {
        "name": "Neurons for ITSM (On-Premises)",
        "vendor": {
          "name": "Ivanti",
          "scada": false
        }
      }
    },
    {
      "description": "Neurons for ITSM (On-Premises) version 2025.4 ant\u00e9rieures \u00e0 2025.4 Patch 1 ",
      "product": {
        "name": "Neurons for ITSM (On-Premises)",
        "vendor": {
          "name": "Ivanti",
          "scada": false
        }
      }
    },
    {
      "description": "Neurons for ITSM (Cloud) version 2026.2 ant\u00e9rieures \u00e0 2026.2 patch 1",
      "product": {
        "name": "Neurons for ITSM (Cloud)",
        "vendor": {
          "name": "Ivanti",
          "scada": false
        }
      }
    }
  ],
  "affected_systems_content": "",
  "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
  "cves": [
    {
      "name": "CVE-2026-9614",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9614"
    }
  ],
  "initial_release_date": "2026-06-02T00:00:00",
  "last_revision_date": "2026-06-02T00:00:00",
  "links": [],
  "reference": "CERTFR-2026-AVI-0677",
  "revisions": [
    {
      "description": "Version initiale",
      "revision_date": "2026-06-02T00:00:00.000000"
    }
  ],
  "risks": [
    {
      "description": "Contournement de la politique de s\u00e9curit\u00e9"
    }
  ],
  "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans les produits Ivanti. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.",
  "title": "Vuln\u00e9rabilit\u00e9 dans les produits Ivanti",
  "vendor_advisories": [
    {
      "published_at": "2026-06-01",
      "title": "Bulletin de s\u00e9curit\u00e9 Ivanti Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614",
      "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614"
    },
    {
      "published_at": "2026-06-01",
      "title": "Bulletin de s\u00e9curit\u00e9 Ivanti june-2026-ivanti-neurons-for-itsm-security-update",
      "url": "https://www.ivanti.com/blog/june-2026-ivanti-neurons-for-itsm-security-update"
    }
  ]
}

CVE-2026-9614 (GCVE-0-2026-9614)
Vulnerability from cvelistv5
Published
2026-06-01 17:50
Modified
2026-06-02 03:56
CWE
  • CWE-284 - Improper Access Control
Summary
An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.
Impacted products
Vendor Product Version
Ivanti Neurons for ITSM (On-Premises) Patch: 2025.4 Patch 1
Patch: 2025.3 Patch 1
Patch: 2025.2 Patch 1
Create a notification for this product.
   Ivanti Neurons for ITSM (Cloud) Patch: 2026.1 Patch 9
Patch: 2026.2 Patch 1
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-9614",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-06-01T00:00:00+00:00",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-02T03:56:03.438Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "product": "Neurons for ITSM (On-Premises)",
          "vendor": "Ivanti",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.4 Patch 1",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "2025.3 Patch 1",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "2025.2 Patch 1",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Neurons for ITSM (Cloud)",
          "vendor": "Ivanti",
          "versions": [
            {
              "status": "unaffected",
              "version": "2026.1 Patch 9",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "2026.2 Patch 1",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "An Improper Access Control vulnerability in Ivanti\u0026nbsp;Neurons for\u0026nbsp;ITSM\u0026nbsp;(cloud and\u0026nbsp;on-premises)\u0026nbsp;allows a remote authenticated attacker to gain administrative access.\u0026nbsp;"
            }
          ],
          "value": "An Improper Access Control vulnerability in Ivanti\u00a0Neurons for\u00a0ITSM\u00a0(cloud and\u00a0on-premises)\u00a0allows a remote authenticated attacker to gain administrative access."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-233",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-233 Privilege Escalation"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-284",
              "description": "CWE-284: Improper Access Control",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-06-01T17:50:03.264Z",
        "orgId": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
        "shortName": "ivanti"
      },
      "references": [
        {
          "url": "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 1.0.2"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
    "assignerShortName": "ivanti",
    "cveId": "CVE-2026-9614",
    "datePublished": "2026-06-01T17:50:03.264Z",
    "dateReserved": "2026-05-26T16:30:29.761Z",
    "dateUpdated": "2026-06-02T03:56:03.438Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-4914 (GCVE-0-2026-4914)
Vulnerability from cvelistv5
Published
2026-04-14 14:15
Modified
2026-04-14 17:20
CWE
  • CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
Summary
Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is required.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-4914",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-04-14T17:19:55.903544Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-04-14T17:20:09.361Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "product": "Neurons for ITSM (On-Premise)",
          "vendor": "Ivanti",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.4"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Neurons for ITSM (Cloud)",
          "vendor": "Ivanti",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.4"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Stored XSS\u0026nbsp;in\u0026nbsp;Ivanti\u0026nbsp;N-ITSM\u0026nbsp;before\u0026nbsp;version 2025.4\u0026nbsp;allows a\u0026nbsp;remote\u0026nbsp;authenticated\u0026nbsp;attacker to\u0026nbsp;obtain limited information from other user sessions.\u0026nbsp;User interaction is required.\u0026nbsp;"
            }
          ],
          "value": "Stored XSS\u00a0in\u00a0Ivanti\u00a0N-ITSM\u00a0before\u00a0version 2025.4\u00a0allows a\u00a0remote\u00a0authenticated\u00a0attacker to\u00a0obtain limited information from other user sessions.\u00a0User interaction is required."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-592",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-592 Stored XSS"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-14T14:15:48.101Z",
        "orgId": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
        "shortName": "ivanti"
      },
      "references": [
        {
          "url": "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4914?language=en_US"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 1.0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
    "assignerShortName": "ivanti",
    "cveId": "CVE-2026-4914",
    "datePublished": "2026-04-14T14:15:48.101Z",
    "dateReserved": "2026-03-26T16:37:45.229Z",
    "dateUpdated": "2026-04-14T17:20:09.361Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-4913 (GCVE-0-2026-4913)
Vulnerability from cvelistv5
Published
2026-04-14 14:10
Modified
2026-04-14 15:07
CWE
  • CWE-424 - Improper Protection of Alternate Path
Summary
Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to retain access when their account has been disabled.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-4913",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-04-14T15:07:39.450225Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-04-14T15:07:48.368Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "product": "Neurons for ITSM (On-Premise)",
          "vendor": "Ivanti",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.4"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Neurons for ITSM (Cloud)",
          "vendor": "Ivanti",
          "versions": [
            {
              "status": "unaffected",
              "version": "2025.4"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "Improper protection of an alternate path\u0026nbsp;in\u0026nbsp;Ivanti\u0026nbsp;N-ITSM\u0026nbsp;before\u0026nbsp;version 2025.4\u0026nbsp;allows a\u0026nbsp;remote authenticated\u0026nbsp;attacker to\u0026nbsp;retain access when their account has been\u0026nbsp;disabled.\u0026nbsp;\u0026nbsp;"
            }
          ],
          "value": "Improper protection of an alternate path\u00a0in\u00a0Ivanti\u00a0N-ITSM\u00a0before\u00a0version 2025.4\u00a0allows a\u00a0remote authenticated\u00a0attacker to\u00a0retain access when their account has been\u00a0disabled."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-554",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-554 Functionality Bypass"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.7,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-424",
              "description": "CWE-424: Improper Protection of Alternate Path",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-04-14T14:10:37.405Z",
        "orgId": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
        "shortName": "ivanti"
      },
      "references": [
        {
          "url": "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4914?language=en_US"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "x_generator": {
        "engine": "Vulnogram 1.0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "3c1d8aa1-5a33-4ea4-8992-aadd6440af75",
    "assignerShortName": "ivanti",
    "cveId": "CVE-2026-4913",
    "datePublished": "2026-04-14T14:10:30.529Z",
    "dateReserved": "2026-03-26T16:37:44.109Z",
    "dateUpdated": "2026-04-14T15:07:48.368Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}