AI analysis
CVE-2026-12646 is a missing authorization flaw (CWE-862) in Ivanti Neurons for ITSM in which privileged requests are not properly permission-checked. A remote attacker holding any valid low-privilege account can send crafted network requests that bypass the authorization check and execute arbitrary code on the server; the changed scope (S:C) in the CVSS score indicates compromise can extend beyond the vulnerable component itself. Successful exploitation has critical impact on confidentiality, integrity and availability (CVSS 3.1 9.9). Any organization running Neurons for ITSM on a release before 2026.2 is affected; the fix shipped in the 2026.2 release as part of a batch of ten Ivanti patches covering EPMM, Neurons for ITSM and Sentry. Exploitation status: no known in-the-wild exploitation, no public proof-of-concept, not listed in CISA KEV, and EPSS estimates roughly a 1.2% probability of exploitation within 30 days.
What to do: Upgrade Ivanti Neurons for ITSM to version 2026.2 or later, which remediates this flaw alongside the other fixes released in the same patch batch. Because exploitation requires an authenticated low-privilege account, review accounts with access to the ITSM server, audit recent authenticated activity for signs of abuse, and restrict network exposure of the server as interim mitigation. Consult Ivanti's advisory for the full set of related EPMM, Neurons for ITSM and Sentry fixes to ensure nothing is missed during patching.
Affected
| Ivanti Neurons for ITSM | all versions before 2026.2 |
Estimated exposure
moderatelikely on the order of thousands of customer deployments (tens of thousands of internal users), exact count unknown — Neurons for ITSM is an enterprise IT service management platform typically deployed as one instance per customer organization (self-hosted or SaaS); no public install or scan counts are available, so the magnitude is extrapolated from…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.