Ivanti ITSM Vulnerability Allows Privilege Escalation for Authenticated Users

Ivanti ITSM Vulnerability Allows Privilege Escalation for Authenticated Users

First seen 3 Jun 2026, 13:28 UTC GbhackersCybersecuritynewshub.ivanti.com 94% similarity 70.5

Article Content

Browse articles
ThreatCluster

Ivanti disclosed a high-severity vulnerability in its Ivanti Neurons for ITSM platform, tracked as CVE-2026-9614, which allows attackers with valid credentials to escalate privileges and gain full administrative access. The flaw affects both cloud and on-premises deployments and has a CVSS score of 8.8, indicating a significant security risk. The vulnerability is classified as an improper access control issue (CWE-284). A patch has been released to address this vulnerability, and organizations are urged to apply it promptly to mitigate the risk of exploitation. This vulnerability poses a critical threat to enterprise environments utilizing Ivanti's ITSM solutions.

Key Points: • CVE-2026-9614 allows authenticated attackers to gain admin access. • The vulnerability affects both cloud and on-premises deployments of Ivanti Neurons for ITSM. • A patch has been released, and organizations are advised to apply it immediately.

ThreatCluster AI

Timeline

2026-06-01
CVE-2026-9614 published
Ivanti disclosed a high-severity vulnerability in its ITSM platform, allowing privilege escalation for authenticated users.
Cybersecuritynews
2026-06-01
Patch released
Ivanti released a patch to fix the vulnerability, urging users to apply it to secure their systems.
Gbhackers

Community

Browse all →