Ivanti Neurons for ITSM CVE-2026-9614 — Improper Access Control Privilege Escalation to Administrator — Threadlinqs Intelligence
As of 2026-06-03, Ivanti Neurons for ITSM CVE-2026-9614 — Improper Access Control Privilege Escalation to Administrator is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 12 indicators of compromise.
Threat ID: TL-2026-0676 · Severity: HIGH · CVSS: 8.8 · Status: ACTIVE · Category: VULNERABILITY
An improper access control flaw (CWE-284) in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote, authenticated, low-privileged attacker to escalate to administrative access with no user
CVE-2026-9614 is a high-severity improper access control vulnerability (CWE-284) affecting Ivanti Neurons for ITSM, Ivanti's IT service management platform deployed across enterprise help-desk, change-management, and asset-management workflows in both cloud (SaaS) and on-premises form factors. The flaw allows a remote attacker who already holds a valid, low-privileged authenticated session to elevate their effective permissions to full administrator without any user interaction or social engineering.
The root cause is an authorization enforcement gap: the application validates that a user is authenticated but fails to consistently enforce role/object-level access control on privileged administrative functions and/or role-assignment operations. As a result, a low-privileged role (for example a standard service-desk analyst or self-service portal user) can invoke administrative endpoints or manipulate role/permission state that should be restricted to administrators. Because the platform brokers identity, workflow approvals, and integrations with downstream systems (Active Directory connectors, email, asset databases, automation runbooks), administrative access on Neurons for ITSM is a high-value pivot: an attacker can create or modify accounts, alter approval workflows, exfiltrate ticket and asset data, tamper with audit configuration, and abuse automation/integration credentials.
The CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H reflects a network-exploitable issue (AV:N) with low attack complexity (AC:L), requiring only low privileges (PR:L) and no user interaction (UI:N), with high impact to confidentiality, integrity, and availability of the ITSM instance. Scope is unchanged (S:U) because the impact is contained to the vulnerable ITSM authorization domain — though that domain itself is security-critical.
Ivanti disclosed the vulnerability in a security advisory published 1 June 2026 (CVE record published the same day, NVD last modified 2 June 2026). The CNA for the CVSS assessment is Ivanti; NVD enrichment was still pending at hunt time. Ivanti's advisory states the company was not aware of any customer exploitation at the time of disclosure, and no public proof-of-concept or indicators of compromise had been released. Cloud customers required no action: Ivanti applied fixes across all cloud environments during the 24-25 May 2026 maintenance windows, landing in cloud build trains 2026.1 Patch 9 and 2026.2 Patch 1. On-premises customers running 2025.4 and earlier must apply Ivanti-published patches: 2025.4 Patch 1 (primary fix) with backported fixes in 2025.3 Patch 1 and 2025.2 Patch 1, distributed via the Ivanti License System / download portal.
This CVE is distinct from the April 2026 medium-severity Neurons for ITSM session-handling flaws (which permitted obtaining user sessions); CVE-2026-9614 is a separate authorization/privilege-escalation defect. Given the network attack vector, low privilege requirement, and broad enterprise deployment of Neurons for ITSM, defenders should treat any unpatched on-premises instance as a priority remediation target and audit administrative role assignments for unexpected grants.
Weaknesses (CWE)
CWE-284, CWE-269
Target sectors: technology, financial, healthcare, government, manufacturing, education
Target regions: Global, North America, Europe
Timeline
- Ivanti begins applying fixes across cloud environments during scheduled maintenance (cloud build 2026.1 Patch 9 / 2026.2 Patch 1).
- Ivanti completes cloud remediation; all cloud customers protected with no customer action required.
- Ivanti publishes security advisory for CVE-2026-9614; CVE record published. Vendor reports no known exploitation and no public PoC/IOCs.
- On-premises patches released: 2025.4 Patch 1 plus backports 2025.3 Patch 1 and 2025.2 Patch 1 via the Ivanti License System portal.
- NVD record last modified; CVSS 8.8 (Ivanti CNA) recorded, NVD enrichment pending. National CERT advisory CERTFR-2026-AVI-0677 published.
- Threadlinqs Intelligence documents the threat with full MITRE mapping, detection guidance, and remediation.
Detections & IOCs
As of 2026-09-01, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 12 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-9614, T1078, T1190, T1068, T1078.004, T1098, T1136, T1098.003, T1685, T1070, T1552