[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCKSShgluzWC5DvNFTreq1k2T_mTncWdbzzJyR5HyO-4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"0ae5b8ff-3669-48f0-a7be-d84b50910b81","ivanti-itsm-vulnerabilities-highlight-critical-patch-and-access-control-gaps","b753eb60-8f58-49f0-882e-155a5f4d7ff7","Ivanti ITSM Vulnerabilities Highlight Critical Patch and Access Control Gaps","Two medium-severity vulnerabilities in Ivanti Neurons for ITSM demonstrate common security weaknesses that can lead to unauthorized access and data theft. CVE-2026-4913 reveals a critical access control flaw where disabled user accounts continue to have system access, violating the principle of least privilege and proper account lifecycle management. CVE-2026-4914 represents a stored cross-site scripting vulnerability that could allow attackers to steal session data and potentially escalate privileges. While these vulnerabilities were patched promptly with no known exploitation, they underscore the importance of timely patching and robust access control mechanisms in IT service management systems.","**Immediate actions:**\n- Update Ivanti Neurons for ITSM to version 2025.4 or later immediately\n- Audit all disabled user accounts to ensure access has been properly revoked\n- Implement input validation and output encoding to prevent XSS attacks\n\n**Long-term improvements:**\n- Establish automated patch management processes for all ITSM and critical business applications\n- Deploy continuous vulnerability scanning for all IT service management platforms\n- Implement regular access reviews to verify account status alignment with user employment status\n\n**Detection measures:**\n- Enable monitoring for authentication attempts from disabled accounts\n- Deploy web application firewalls to detect and block XSS attack patterns",[12,13,14,15,16,17],"CIS Control 7","CIS Control 6","NIST AC-2","NIST SI-2","NIST SI-10","OWASP Top 10","published","2026-04-15T13:08:27.697242+00:00","2026-04-15T13:08:27.602+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Ftwo-vulnerabilities-patched-in-ivanti-neurons-for-itsm\u002F","two-vulnerabilities-patched-in-ivanti-neurons-for-itsm-d3a1c9","Two Vulnerabilities Patched in Ivanti Neurons for ITSM",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]