The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check your Ivanti Neurons for ITSM version number and confirm whether it is earlier than 2026.2.
If you are on a version before 2026.2, schedule an urgent upgrade to Ivanti Neurons for ITSM 2026.2.
After upgrading, verify the new version is actually running and that remote administration endpoints (if any) are only reachable from trusted networks.
Review authentication logs for low-privilege logins from remote IPs around the last configuration/changes, and investigate anything unusual.
A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.
In plain language
Written by AI from the record
CVE-2026-12647 is a serious break-in risk in Ivanti Neurons for ITSM: if someone logs in with low privileges, they may be able to run commands and take control of your server remotely. If you use Ivanti Neurons for ITSM, you should act now and upgrade to 2026.2 or later.
Missing Authorization in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker with low privileges to bypass access controls and execute arbitrary code on the server via a network-accessible action without user interaction.
If you're affected
Full server takeover
Customer/support data exposure
Service outage and downtime
Malware installation and persistence
What is it
This is a security flaw in Ivanti Neurons for ITSM where, after an attacker successfully logs in (even with limited access), the normal permission checks can be bypassed. That could let them run harmful commands on the server—like planting malicious software or taking over the system. Think of it like an office door that still opens after a badge swipe, but then lets someone into rooms they shouldn’t reach.
Who is affected
This matters if your business uses Ivanti Neurons for ITSM and it’s running a version before 2026.2. The attacker still needs to be able to authenticate, but only with low privileges, and there’s no need for a user to click anything. Treat this as a risk when your Neurons for ITSM is reachable over the network from untrusted locations and an attacker can obtain valid credentials.
How urgent is it
This is RED because the weakness can result in arbitrary code execution on the server, meaning attackers could directly compromise the system after gaining low-privilege access. The fix is available (2026.2), so you should prioritize upgrading immediately to eliminate the exposed authorization bypass path.
What to do — in detail
Confirm exposure
Identify the deployed Ivanti Neurons for ITSM version.
Determine whether it is before 2026.2 (the known fixed boundary in the available findings).
Upgrade to the fixed version
Upgrade Ivanti Neurons for ITSM to 2026.2.
Ensure the upgrade completed successfully and that the running application reports 2026.2 or later.
If you have multiple environments (prod/test/dev), prioritize production first.
Validate network reachability (reduce risk while patching)
If your Neurons for ITSM instance is reachable from the internet or from broad internal networks, restrict access to trusted IP ranges or a VPN/bastion where possible.
Confirm any remote management or API routes aren’t broadly exposed beyond what’s required.
Check for suspicious access patterns (especially low-privilege logins)
Review logs for successful logins by low-privileged accounts from remote IPs.
Look for unusual timing, new IPs, repeated failed attempts followed by success, or activity inconsistent with normal operations.
If you find anything suspicious, preserve logs and investigate for signs of command execution.
CISA/KEV status
This CVE is not listed in CISA KEV based on the provided findings, but it is still critical due to the impact described.
What to monitor after patching
Ongoing authentication activity (success/failure, source IPs, and account usage).
Any administrative actions or unexpected server-side changes that could indicate attempted abuse.
Technical context
Severity is effectively critical due to the described outcome: authenticated remote arbitrary code execution on Ivanti Neurons for ITSM. The weakness is a missing authorization control (CWE-862), where an authenticated user with low privileges can bypass standard restrictions and perform unauthorized actions. The attack vector is network-based, and there is no user interaction required. The provided findings indicate preconditions of remote authenticated access with low privileges; default reachability is not confirmed in the findings. Exploitation status: KEV listing is not present, and no clear dated press claim or public exploit code is reported in the findings. A predicted likelihood (EPSS) is provided in the source set, but since KEV/news confirm exploitation were not found here, it is not used to drive public-facing guidance. Fix: Ivanti neurons for itsm is fixed in 2026.2.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.