AI analysis
CVE-2026-12647 is a missing authorization flaw (CWE-862) in Ivanti Neurons for ITSM in versions before 2026.2, where certain requests are not properly checked against the user's permissions. A remote attacker who holds any authenticated, low-privileged account can send crafted requests that bypass the authorization check, with no user interaction required. The outcome is arbitrary code execution on the ITSM server, and the scope-changed CVSS rating indicates the impact extends beyond the vulnerable component, consistent with a full server compromise. Any organization running an affected Ivanti Neurons for ITSM deployment (on-premises or hosted) prior to 2026.2 is exposed. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 1.2%, though it was patched alongside a batch of ten Ivanti flaws spanning EPMM, Neurons for ITSM and Sentry.
What to do: Upgrade Ivanti Neurons for ITSM to 2026.2 or later per Ivanti's advisory, which also covers the other recently disclosed EPMM, Neurons and Sentry flaws. Until patched, audit which authenticated accounts (especially low-privilege and self-service users) can reach the ITSM application and enforce least privilege. Monitor ITSM servers for unexpected processes or code execution as a sign of exploitation.
Affected
| Ivanti Neurons for ITSM | all versions before 2026.2 |
Estimated exposure
large≈10,000–50,000 enterprise deployments (server or SaaS instances of Ivanti's ITSM/Service Manager product line) — Ivanti's service-management platform (formerly HEAT/Service Manager) is used by a low-tens-of-thousands customer base within Ivanti's ~40,000-customer enterprise install base, with each customer typically running one or more server…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.