Critical Ivanti ITSM CVE-2023-35083 Lets Attackers Gain Admin Privilege
Key Takeaways A critical privilege escalation vulnerability, CVE-2026-9614, has been identified in Ivanti Neurons for ITSM. The flaw allows authenticated attackers to gain full administrative access...
Key Takeaways
- A critical privilege escalation vulnerability, CVE-2026-9614, has been identified in Ivanti Neurons for ITSM.
- The flaw allows authenticated attackers to gain full administrative access to both cloud and on-premises deployments.
- Rated with a CVSS score of 8.8, the vulnerability poses a high risk due to improper access control.
- Patches are available for on-premises versions, and cloud environments have already been updated by Ivanti.
- While no active exploitation has been detected, immediate patching and access control audits are strongly recommended.
Ivanti has issued a high-priority disclosure regarding a significant security vulnerability affecting its Ivanti Neurons for ITSM platform. This flaw enables authenticated attackers to escalate their privileges, ultimately achieving complete administrative control over affected systems.
Table Of Content
Designated as CVE-2026-9614, the vulnerability impacts both Ivanti’s cloud-hosted and customer-managed on-premises deployments. It carries a severe CVSS rating of 8.8, underscoring the substantial security risk it presents within enterprise IT environments. The root cause of this vulnerability is an improper access control mechanism, categorized under CWE-284.
According to Ivanti, a remote attacker, once authenticated with valid credentials, can exploit this issue without requiring any additional user interaction. This allows for an unauthorized elevation of privileges to an administrator level.
The CVSS vector analysis indicates that the attack can be executed over a network with low complexity and requires only limited user privileges, yet it has the potential to compromise the confidentiality, integrity, and availability of the system.
Ivanti ITSM Vulnerability Details
Ivanti Neurons for ITSM is a widely adopted platform crucial for managing IT services, encompassing functions such as incident ticketing, asset management, and workflow automation. Gaining administrative access to such a system could expose sensitive organizational data, enable threat actors to manipulate system configurations, or facilitate the creation of persistent backdoors.
For instance, an attacker who has compromised low-level credentials could leverage CVE-2026-9614 to escalate their privileges, allowing them to alter user roles and effectively seize control of the entire ITSM environment. The vulnerability specifically affects on-premises versions of Ivanti Neurons for ITSM, including version 2025.4 and all earlier releases.
Ivanti has promptly released patches to mitigate this issue. These fixes are available in version 2025.4 Patch 1, with backported solutions also provided in 2025.3 Patch 1 and 2025.2 Patch 1. Organizations operating affected on-premises versions are strongly advised to update their systems immediately via the Ivanti License System portal.
For cloud-based customers, Ivanti has already implemented the necessary fixes across all environments. The company confirmed that these patches were deployed during scheduled updates on May 24 and 25, specifically in versions 2026.1 Patch 9 and 2026.2 Patch 1.
Subsequent updates were also released to address a separate logging issue related to IP address tracking. However, Ivanti clarified that this secondary bug is distinct and unrelated to the core privilege escalation vulnerability.
At the time of disclosure, Ivanti stated that there was no evidence of active exploitation of CVE-2026-9614 in the wild. Nevertheless, given the ease of exploitation and the potential severe impact, the company issued an out-of-band security advisory to expedite remediation efforts. Ivanti also noted that no publicly available indicators of compromise are currently associated with this vulnerability.
What You Should Do
- Patch Immediately: On-premises customers running Ivanti Neurons for ITSM versions 2025.4 or earlier must apply the latest patches (2025.4 Patch 1, 2025.3 Patch 1, or 2025.2 Patch 1) available through the Ivanti License System portal.
- Verify Cloud Updates: Cloud customers should confirm that their environments have been updated by Ivanti, specifically to versions 2026.1 Patch 9 or 2026.2 Patch 1.
- Audit Access Controls: Conduct a thorough audit of role-based access controls within your ITSM deployments. Ensure that administrative privileges are strictly limited to necessary personnel.
- Review Permissions: Regularly review and verify all access permissions within your ITSM environment to prevent misconfigurations that could facilitate exploitation.
- Stay Informed: Monitor official Ivanti security advisories for any further updates or recommendations regarding this vulnerability.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.