Stored XSS Vulnerability in Ivanti N-ITSM
CVE-2026-4914

5.4MEDIUM

What is CVE-2026-4914?

A stored cross-site scripting vulnerability in Ivanti N-ITSM prior to version 2025.4 permits a remote authenticated attacker to extract limited information from other users’ sessions. This can occur when specific user interactions happen, enabling attackers to exploit the flaw and access sensitive data from compromised user accounts.

Affected Version(s)

Neurons for ITSM (Cloud) 2025.4

Neurons for ITSM (On-Premise) 2025.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.