
Ivanti Neurons for ITSM の脆弱性 CVE-2026-4913/4914 が FIX:ユーザーセッション窃取の恐れ https://iototsecnews.jp/2026/04/14/ivanti-neurons-for-itsm-vulnerabilities-allow-remote-attacker-to-obtain-user-sessions/ 1 つ目の脆弱性 CVE-2026-4913 は、システム内の代替パスに対する不十分な防御に起因します。これにより、本来はアクセスできない経路から、認証状態を維持されてしまうリスクが生じました。2 つ目の脆弱性 CVE-2026-4914 は、蓄積型 XSS の脆弱性です。入力データに対する不適切な検証や無害化により、悪意のスクリプトが保存され、他ユーザーのセッション情報を盗み見られる状態になっていました。ご利用のチームは、ご注意ください。 #CVE20264913 #CVE20264914 #Ivanti #NeuronsforITSM #Vulnerability
Post summary
The article announces that two CVEs (CVE‑2026‑4913 and CVE‑2026‑4914) in Ivanti Neurons for ITSM have been fixed, providing technical details of the session fixation and stored XSS issues, and recommends teams remain cautious pending the patch.




