CVE-2026-4914Disclosure

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is required.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-19); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Mentions · 2026-04-19: 2Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-19: 2Technical Details · 2026-04-21: 104-1404-1504-1904-21
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-151
Patch1
2026-04-192
Disclosure2
2026-04-211
Patch1
Full discourse5 posts
  • iototsecnews@iototsecnews
    Patch

    Ivanti Neurons for ITSM の脆弱性 CVE-2026-4913/4914 が FIX:ユーザーセッション窃取の恐れ https://iototsecnews.jp/2026/04/14/ivanti-neurons-for-itsm-vulnerabilities-allow-remote-attacker-to-obtain-user-sessions/ 1 つ目の脆弱性 CVE-2026-4913 は、システム内の代替パスに対する不十分な防御に起因します。これにより、本来はアクセスできない経路から、認証状態を維持されてしまうリスクが生じました。2 つ目の脆弱性 CVE-2026-4914 は、蓄積型 XSS の脆弱性です。入力データに対する不適切な検証や無害化により、悪意のスクリプトが保存され、他ユーザーのセッション情報を盗み見られる状態になっていました。ご利用のチームは、ご注意ください。 #CVE20264913 #CVE20264914 #Ivanti #NeuronsforITSM #Vulnerability

    Post summary

    The article announces that two CVEs (CVE‑2026‑4913 and CVE‑2026‑4914) in Ivanti Neurons for ITSM have been fixed, providing technical details of the session fixation and stored XSS issues, and recommends teams remain cautious pending the patch.

    01000101
    486 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Two vulnerabilities in Ivanti Neurons ITSM (CVE-2026-4913 & CVE-2026-4914) allow session persistence and stored XSS to expose session data. Cloud fixes released Dec 12, 2025; on-prem users must update via Ivanti License System. #IvantiFix #SessionHijack https://ift.tt/pXNTrUd

    Post summary

    The post announces two CVEs affecting Ivanti Neurons ITSM that enable session persistence and stored XSS to expose session data, and confirms that cloud patches were released on Dec 12, 2025, with on‑prem users urged to update via the Ivanti License System.

    00010164
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4914 Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is req… https://www.cve.org/CVERecord?id=CVE-2026-4914 ----- Traducción: CVE-2026-4914 XSS… http://infoflow.cloud`

    Post summary

    The entry announces CVE‑2026‑4914, a Stored XSS flaw in Ivanti N‑ITSM, outlining its impact and referencing the official CVE record.

    0000046
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4914 Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is req… https://www.cve.org/CVERecord?id=CVE-2026-4914

    Post summary

    The text announces CVE‑2026‑4914, a stored‑XSS flaw in Ivanti N‑ITSM that lets authenticated attackers read limited data from other sessions, and highlights that upgrading to version 2025.4 resolves the issue.

    00000380
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚡ CVE-2026-4914: Ivanti (CVSS: 5.4)... Another Ivanti XSS turning ITSM sessions into data leakage goldmines - authenticated attackers can pivot across user con... https://zerodaysignal.com/vulnerability/CVE-2026-4914 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-4914, an authenticated XSS in Ivanti ITSM that can leak data across user contexts, providing its CVSS score and a link for further details but no exploit or patch information.

    0000062
    218 followersView on X

Explore more