CVE-2026-4913Disclosure

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to retain access when their account has been disabled.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-424

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 2 mentions (2026-04-14); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Mentions · 2026-04-19: 2Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-14: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-19: 2Technical Details · 2026-04-21: 104-1404-1504-1904-21
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure2
2026-04-151
Patch1
2026-04-192
Disclosure2
2026-04-211
Patch1
Full discourse6 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    ぱっちちゅーずでー ◆ Microsoft 2026 年 4 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/04/202604-security-update CVE-2026-33825 Microsoft Defender の特権の昇格の脆弱性 CVE-2026-32201 Microsoft SharePoint Server のなりすましの脆弱性 ◆Fortinet https://fortiguard.fortinet.com/psirt ・FG-IR-26-100 / CVE-2026-39808 FortiSandbox 4.4系のAPIにある OSコマンドインジェクション。細工したリクエストを受けると、認証なしで任意コードや任意コマンドを実行される恐れがあります。外部公開や到達可能性がある環境では、優先度高めでの確認が必要です。 ・FG-IR-26-112 / CVE-2026-39813 FortiSandbox のJRPC APIにある パストラバーサル起因の認証回避・権限昇格。特別に細工したHTTPリクエストで未認証のまま認証をバイパスし、権限を引き上げられる可能性があるため、管理API露出環境では特に注意が必要です。 ・FG-IR-26-121 / CVE-2026-22828 FortiAnalyzer Cloud / FortiManager Cloud の oftpd にある ヒープベースのバッファオーバーフロー。細工したリクエストにより、リモートの未認証攻撃者が任意コードやコマンド実行に至る可能性がありますが、悪用にはASLRや分離構成を踏まえた準備が必要です。 ◆Ivanti https://www.ivanti.com/blog/april-2026-security-update https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-4913-CVE-2026-4… ◆Adobe(Criticalで任意のコード実行のみ抽出) https://helpx.adobe.com/security.html ・Adobe ColdFusion(APSB26-38) CVE-2026-27304, CVE-2026-27306 入力検証不備により、任意のコード実行につながる脆弱性 ・Adobe Connect(APSB26-37) CVE: CVE-2026-27302, CVE-2026-27303, CVE-2026-27243, CVE-2026-27245, CVE-2026-27246, CVE-2026-34615 デシリアライズ不備や XSS を起点に、任意のコード実行が可能となる脆弱性 ・Adobe FrameMaker(APSB26-36) CVE: CVE-2026-27290, CVE-2026-27292, CVE-2026-27293, CVE-2026-27294, CVE-2026-27295, CVE-2026-27296, CVE-2026-27297, CVE-2026-27298 任意のコード実行につながる脆弱性群 ・Adobe Bridge(APSB26-39) CVE: CVE-2026-34630, CVE-2026-27310, CVE-2026-27311, CVE-2026-27312, CVE-2026-27313 複数のヒープベース・バッファオーバーフローにより、任意のコード実行が可能になる脆弱性 ・Adobe Photoshop(APSB26-40) CVE: CVE-2026-27289 境界外読み取りにより、任意のコード実行につながる脆弱性 ・Adobe Illustrator(APSB26-42) CVE: CVE-2026-34618 境界外書き込みにより、任意のコード実行につながる脆弱性 ◆SAP SAP Security Patch Day - April 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/april-2026.html CVE-2026-27681 https://www.cve.org/CVERecord?id=CVE-2026-27681 『(直訳)SAP Business Planning and ConsolidationおよびSAP Business Warehouseにおける認証チェックの不備により、認証済みのユーザーが細工されたSQL文を実行してデータベースデータを読み取り、変更、削除できる脆弱性が存在します。これは、システムの機密性、完全性、可用性に重大な影響を及ぼします。』

    Post summary

    The message compiles an April 2026 security update agenda for several vendors, listing multiple CVEs with technical details, but offers no PoC, exploit code, active exploitation reports, or patch information.

    000321.4K
    11.7K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Ivanti Neurons for ITSM の脆弱性 CVE-2026-4913/4914 が FIX:ユーザーセッション窃取の恐れ https://iototsecnews.jp/2026/04/14/ivanti-neurons-for-itsm-vulnerabilities-allow-remote-attacker-to-obtain-user-sessions/ 1 つ目の脆弱性 CVE-2026-4913 は、システム内の代替パスに対する不十分な防御に起因します。これにより、本来はアクセスできない経路から、認証状態を維持されてしまうリスクが生じました。2 つ目の脆弱性 CVE-2026-4914 は、蓄積型 XSS の脆弱性です。入力データに対する不適切な検証や無害化により、悪意のスクリプトが保存され、他ユーザーのセッション情報を盗み見られる状態になっていました。ご利用のチームは、ご注意ください。 #CVE20264913 #CVE20264914 #Ivanti #NeuronsforITSM #Vulnerability

    Post summary

    The advisory announces that CVE-2026-4913 and CVE-2026-4914 in Ivanti Neurons for ITSM have been patched, explaining that the flaws were an authentication bypass via alternative paths and a stored XSS capable of stealing user sessions.

    01000101
    486 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Two vulnerabilities in Ivanti Neurons ITSM (CVE-2026-4913 & CVE-2026-4914) allow session persistence and stored XSS to expose session data. Cloud fixes released Dec 12, 2025; on-prem users must update via Ivanti License System. #IvantiFix #SessionHijack https://ift.tt/pXNTrUd

    Post summary

    The note announces that two Ivanti Neurons ITSM vulnerabilities (CVE‑2026‑4913 & CVE‑2026‑4914) were fixed in the cloud on Dec 12 2025; on‑prem users must apply updates via the Ivanti License System to address session persistence and stored XSS issues.

    00010164
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4913 Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to retain access when their account has been disa… https://www.cve.org/CVERecord?id=CVE-2026-4913 ----- Traducción: CVE-2026-4913 Pro… http://infoflow.cloud`

    Post summary

    The post discloses CVE‑2026‑4913, highlighting a remote authenticated attacker bypass that allows persistent access in Ivanti N‑ITSM versions before 2025.4. No PoC, exploit code, or patch details are provided.

    0000049
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4913 Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to retain access when their account has been disa… https://www.cve.org/CVERecord?id=CVE-2026-4913

    Post summary

    This advisory highlights that CVE-2026-4913 in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to retain access via improper path protection; the issue is mitigated in newer releases.

    00000406
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚡ CVE-2026-4913: Ivanti (CVSS: 5.7)... Disabled accounts staying active through alternate paths = persistent access goldmine for lateral movement once you're a... https://zerodaysignal.com/vulnerability/CVE-2026-4913 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new vulnerability, CVE-2026-4913, has been disclosed with a CVSS score of 5.7, enabling attackers to maintain persistent access via disabled accounts, which could facilitate lateral movement. No patch, exploit, or active exploitation anecdotes are reported.

    0000057
    218 followersView on X

Explore more