🔐 CVE Alert

CVE-2026-4913

MEDIUM 5.7
CVSS Score
5.7
EPSS Score
0.0%
EPSS Percentile
0th

Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to retain access when their account has been disabled.

CWE CWE-424
Vendor ivanti
Product neurons for itsm (on-premise)
Ecosystems
Industries
SecurityNetworking
Published Apr 14, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for ivanti neurons for itsm (on-premise)

Be the first to know when new medium vulnerabilities affecting ivanti neurons for itsm (on-premise) are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Ivanti / Neurons for ITSM (On-Premise)
All versions affected
Ivanti / Neurons for ITSM (Cloud)
All versions affected

References

NVD ↗ CVE.org ↗ EPSS Data ↗
hub.ivanti.com: https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4914?language=en_US