Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN751
_____________________________________________________________________


DATE                : 16/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Ivanti Xtraction versions prior
                                    to 2026.2.1.
 
=====================================================================

https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Xtraction-CVE-2026-14902-CVE-2026-14903?language=en_US
_____________________________________________________________________



Security Advisory Ivanti Xtraction (CVE-2026-14902, CVE-2026-14903)

Primary Product
Xtraction

Created Date
14-Jul-2026 9:01:16

Last Modified Date
14-Jul-2026 14:11:34

Ivanti has released updates for Ivanti Xtraction which addresses one
medium and one high vulnerability.  

We are not aware of any customers being exploited by these
vulnerabilities at the time of disclosure. 

 
 

Vulnerability Details: 

CVE Number   Description   CVSS Score (Severity)  CVSS Vector 
CWE 

CVE-2026-14902 
An open redirect in Ivanti Xtraction before version 2026.2.1
allows a remote unauthenticated attacker to redirect users
to arbitrary external URLs. 
4.0 (Medium) 
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N 
CWE-601 

CVE-2026-14903 
Path traversal in Ivanti  Xtraction before version 2026.2.1
allows a remote authenticated attacker to read arbitrary
files outside the web root. 
7.7 (High) 
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N 
CWE-23 

 

Affected Versions

Product Name   Affected Version(s)    Affected CPE(s) 
Resolved Version(s)     Patch Availability 

Ivanti Xtraction     2026.2 and prior 
cpe:2.3:a:ivanti:xtraction:2026.2:*:*:*:*:*:*:* 
2026.2.1 
Download Available in ILS 


Solution 

Customers can resolve these vulnerabilities by updating
to Ivanti Xtraction 2026.2.1, available in ILS.   
 
 

Note: Ivanti is dedicated to ensuring the security and
integrity of our enterprise software products. We recognize
the vital role that security researchers, ethical hackers,
and the broader security community play in identifying and
reporting vulnerabilities. Visit HERE to learn more about
our Vulnerability Disclosure Policy. 


FAQ 

1. Are you aware of any active exploitation of these
vulnerabilities? 

We are not aware of any customers being exploited by these
vulnerabilities prior to public disclosure. These
vulnerabilities were disclosed through our responsible
disclosure program.   

2. How can I tell if I have been compromised? 

Currently, there is no known public exploitation of these
vulnerabilities that could be used to provide a list of
indicators of compromise. 

3. What should I do if I need help?

If you have questions after reviewing this information,
you can log a case and/or request a call via the Ivanti
Innovators Hub. 

Article Number :
000107769

Article Promotion Level
Normal


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




