Sceawere
Vulnerability Detail
CVE-2026-12645UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ivanti Neurons Arbitrary Code Execution
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 3h ago
- Vendor
- Ivanti
- Product
- Ivanti Neurons for ITSM
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-09-08T15:18:40.380Z",
"pubdate": "2026-09-08T15:18:40.380Z",
"executiveSummary": "This vulnerability involves a Missing Authorization flaw within Ivanti Neurons for ITSM, classified as a critical security defect.\nThe flaw allows a remote authenticated attacker to bypass authorization controls, facilitating the execution of arbitrary code directly on the host server.\nThe affected product is Ivanti Neurons for ITSM, specifically all versions prior to 2026.2.\nThe risk implications are severe, as arbitrary code execution typically grants the adversary complete control over the application environment, potentially leading to unauthorized data access, system compromise, and lateral movement within the network.\nThe exploitation requirement is limited to an authenticated attacker, meaning an adversary must first possess legitimate credentials or a compromised session to trigger the vulnerable code path.\nOnce authorization checks are bypassed, the attacker can leverage the underlying system vulnerabilities to execute malicious payloads, resulting in a full system compromise.",
"technicalDetails": "The vulnerability resides in the authorization logic of Ivanti Neurons for ITSM, where specific server-side operations fail to properly validate the authorization context of the requester.\nThe root cause is a Missing Authorization flaw, likely occurring during the processing of incoming requests where the application assumes that the user context provided by the transport layer is inherently authorized for administrative or system-level functions.\nBecause the server fails to verify whether the authenticated user possesses the appropriate permissions to perform sensitive operations, an attacker can invoke restricted functions that facilitate command execution.\nThe attack flow begins with the authenticated user interacting with the target application through legitimate endpoints. By manipulating request parameters or calling specific internal application methods, the attacker bypasses standard access control lists (ACLs) that should otherwise prohibit such actions.\nUpon successful invocation of the vulnerable component, the application executes the supplied input in the context of the service account running the Ivanti Neurons for ITSM process. This effectively elevates the attacker's capabilities, allowing for arbitrary code execution on the underlying operating system.\nThe scope of the impact is broad; successful exploitation allows the adversary to bypass security boundaries, potentially leading to the installation of persistent backdoors, data exfiltration, or the deployment of ransomware within the server environment.\nSince the vulnerability is triggered via a remote request, the network exposure is significant if the service is accessible over a network without robust segmentation. The lack of granular authorization checks at the functional level allows the adversary to perform unauthorized tasks that would typically require higher administrative privileges than the attacker currently holds.\nPost-exploitation activities are limited only by the privileges of the service account configured for the Ivanti Neurons application. This often results in high-level system access, enabling the attacker to manipulate database records, modify system files, or intercept internal application traffic, significantly undermining the overall integrity and confidentiality of the ITSM infrastructure."
}