Ivanti Neurons
cpe:2.3:a:ivanti:neurons_for_itsm:*:*:*:*:*:*:*
- <= 2025.4
- <= 2026.1
A vulnerability allowing improper access control has been identified in Ivanti Neurons for ITSM, both in cloud and on-premises versions. This vulnerability enables a remote authenticated attacker to gain administrative access. It arises from inadequate access control measures, allowing unauthorized elevation of privileges.
Exploitation of this vulnerability could lead to unauthorized administrative access, allowing attackers to gain elevated privileges within the application.
Users of Ivanti Neurons for ITSM on-premises can update to version 2025.4 Patch 1, 2025.3 Patch 1, or 2025.2 Patch 1. For cloud users, the update has already been applied.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.