AI analysis
CVE-2026-12645 is a critical Missing Authorization flaw (CWE-862) in Ivanti Neurons for ITSM, Ivanti's IT service management platform, where functionality on the server can be reached without the required authorization checks. A remote attacker who already holds valid low-privileged credentials can trigger the flaw with crafted requests to the affected component, and because the check is absent they can execute arbitrary code on the server. The CVSS scope-changed metric (S:C) indicates that successful exploitation may impact resources beyond the vulnerable component, with high impact to confidentiality, integrity, and availability. Organizations running Ivanti Neurons for ITSM in versions before 2026.2 are affected; the fix shipped as part of a batch of 10 patches across Ivanti's EPMM, Neurons for ITSM, and Sentry products. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS currently estimates about a 1.2% probability of exploitation in the next 30 days.
What to do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later per Ivanti's advisory. Until patched, restrict which accounts can reach the platform, watch for anomalous authenticated activity and unexpected server-side code execution, and check Ivanti's advisory for any interim mitigation or workaround guidance. Because exploitation requires valid credentials, also review accounts with low-privileged access to the ITSM instance for signs of compromise.
Affected
| Ivanti Neurons for ITSM | all versions before 2026.2 |
Estimated exposure
largeroughly 1,000-10,000 enterprise deployments/tenants, with aggregate internal users plausibly in the hundreds of thousands (exact counts not publicly published) — Neurons for ITSM is deployed once per organization (on-prem or SaaS tenant) rather than as millions of endpoints, and Ivanti serves a very large enterprise customer base across its portfolio, so the plausible order of magnitude is…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.