🔐 CVE Alert

CVE-2026-4914

MEDIUM 5.4
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is required.

CWE CWE-79
Vendor ivanti
Product neurons for itsm (on-premise)
Ecosystems
Industries
SecurityNetworking
Published Apr 14, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for ivanti neurons for itsm (on-premise)

Be the first to know when new medium vulnerabilities affecting ivanti neurons for itsm (on-premise) are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Ivanti / Neurons for ITSM (On-Premise)
All versions affected
Ivanti / Neurons for ITSM (Cloud)
All versions affected

References

NVD ↗ CVE.org ↗ EPSS Data ↗
hub.ivanti.com: https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4914?language=en_US