Stored XSS Vulnerability in Ivanti N-ITSM
CVE-2026-4914
5.4MEDIUM
Key Information:
- Vendor
Ivanti
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-4914?
A stored cross-site scripting vulnerability in Ivanti N-ITSM prior to version 2025.4 permits a remote authenticated attacker to extract limited information from other users’ sessions. This can occur when specific user interactions happen, enabling attackers to exploit the flaw and access sensitive data from compromised user accounts.
Affected Version(s)
Neurons for ITSM (Cloud) 2025.4
Neurons for ITSM (On-Premise) 2025.4