Ivanti patches two Neurons for ITSM flaws that can preserve access or expose session data


Ivanti has released security fixes for two medium-severity vulnerabilities in Ivanti Neurons for ITSM, its IT service management platform. The issues, tracked as CVE-2026-4913 and CVE-2026-4914, affect versions before 2025.4 and could let an authenticated attacker keep access after account disablement or pull limited data from other users’ sessions.

The first flaw, CVE-2026-4913, is an improper protection of an alternate path issue. Ivanti says a remote authenticated attacker could retain access even after an administrator disables the account, which makes the bug especially relevant for offboarding, privilege revocation, and insider-risk scenarios.

The second flaw, CVE-2026-4914, is a stored cross-site scripting bug. Ivanti says it allows a remote authenticated attacker to obtain limited information from other user sessions, and user interaction is required for exploitation.

What is affected and what needs action

Both CVEs affect Ivanti N-ITSM before version 2025.4. Ivanti says on-premise customers should update to version 2025.4 through the Ivanti License System, while cloud customers do not need to take action because the fix was already applied to all cloud environments on December 12, 2025.

Ivanti also says it is not aware of active exploitation of either vulnerability at the time of disclosure. That lowers the immediate alarm level, but it does not change the need to patch on-premise deployments because both flaws require only low privileges and affect core session trust and access control.

From a risk perspective, CVE-2026-4913 may worry defenders more because it touches account disablement, which many organizations treat as a hard security boundary. CVE-2026-4914 is less severe on paper, but it can still expose session-linked information if a user opens malicious stored content. This last sentence is an inference based on the CNA descriptions and CVSS vectors.

Severity and impact at a glance

CVEIssue typeSeverityMain impactUser interaction
CVE-2026-4913Improper protection of alternate pathMedium 5.7Disabled account may retain accessRequired
CVE-2026-4914Stored XSSMedium 5.4Limited information exposure from other user sessionsRequired

Source: Ivanti CNA data in NVD.

What admins should do now

  • Upgrade on-premise Ivanti Neurons for ITSM systems to version 2025.4.
  • Confirm whether any recently disabled accounts still show post-disable activity. This is a practical response based on the nature of CVE-2026-4913.
  • Review stored content, custom fields, and user-generated inputs that could surface in other sessions. This follows from the stored XSS behavior described for CVE-2026-4914.
  • Keep cloud environments on the radar, but note that Ivanti says hosted instances already received the fix in December 2025.
  • Watch for Ivanti follow-up guidance in case the company publishes additional detection or support notes.

FAQ

What is the more serious Ivanti Neurons for ITSM flaw?

By score, CVE-2026-4913 is slightly more severe at 5.7 versus 5.4 for CVE-2026-4914. It can let an authenticated attacker keep access after an account has been disabled.

Does this affect Ivanti cloud customers?

Ivanti says cloud customers do not need to take action because it already applied the fix to all cloud environments on December 12, 2025.

Do on-premise customers need to patch manually?

Yes. Ivanti says on-premise customers should update to version 2025.4 through the Ivanti License System.

Has Ivanti seen active exploitation?

Ivanti says it is not aware of active exploitation of either vulnerability at disclosure time.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages