Gbhackers
Ivanti ITSM Vulnerability Allows Privilege Escalation for Authenticated Users
Article Content
Ivanti disclosed a high-severity vulnerability in its Ivanti Neurons for ITSM platform, tracked as CVE-2026-9614, which allows attackers with valid credentials to escalate privileges and gain full administrative access. The flaw affects both cloud and on-premises deployments and has a CVSS score of 8.8, indicating a significant security risk. The vulnerability is classified as an improper access control issue (CWE-284). A patch has been released to address this vulnerability, and organizations are urged to apply it promptly to mitigate the risk of exploitation. This vulnerability poses a critical threat to enterprise environments utilizing Ivanti's ITSM solutions.
Key Points: • CVE-2026-9614 allows authenticated attackers to gain admin access. • The vulnerability affects both cloud and on-premises deployments of Ivanti Neurons for ITSM. • A patch has been released, and organizations are advised to apply it immediately.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.