

Ivanti Xtraction versions 2026.2 and prior, across all supported deployment types. Fixed in version 2026.2.1, available via the Ivanti Licensing Server (ILS).
Ivanti disclosed two vulnerabilities in Xtraction, its data visualisation and reporting platform. The more severe flaw, CVE-2026-14903 (CVSS 7.7), is a path traversal vulnerability allowing a remote authenticated attacker to read arbitrary files located outside the web root on the underlying server. The second vulnerability, CVE-2026-14902 (CVSS 4.0), is an open redirect that allows a remote unauthenticated attacker to redirect users to arbitrary external URLs, which can be leveraged in phishing and credential harvesting attacks.
Advisory published 15 July 2026. No active exploitation confirmed at time of publication. Fixed version 2026.2.1 is available immediately via the Ivanti Licensing Server. The standard recommended remediation window is ten working days.
CVE-2026-14903 requires authenticated access to Xtraction. CVE-2026-14902 is exploitable by unauthenticated attackers who can craft and distribute malicious redirect URLs. Any internet-accessible Xtraction deployment is exposed to the open redirect, and any authenticated user with access to the platform can potentially exploit the path traversal.
CVE-2026-14903 allows a remote authenticated attacker to read arbitrary files outside the Xtraction web root. Depending on server configuration, this could expose sensitive files including configuration files, credentials, internal application data, and potentially operating system files accessible to the web application process. CVE-2026-14902 allows unauthenticated attackers to abuse the platform's redirect mechanism to send users to attacker-controlled sites, facilitating phishing, credential theft, and social engineering attacks that leverage the legitimacy of the Xtraction domain.
Risk is rated High across all government and business entity sizes. Xtraction is commonly deployed in environments that aggregate data from IT service management and business intelligence platforms, meaning the data accessible via path traversal could include sensitive operational or financial information. The open redirect risk is amplified in organisations where Xtraction is a trusted and recognised internal tool, increasing the likelihood that users will follow redirect links without suspicion.
Upgrade Ivanti Xtraction to version 2026.2.1 immediately via the Ivanti Licensing Server. No workarounds are documented for either vulnerability; patching is the only remediation. Establish and maintain a documented vulnerability management and remediation process to ensure future advisories are actioned within the ten-working-day window. Conduct automated vulnerability scans of both internal and externally-exposed assets on a regular basis.
Apply the Principle of Least Privilege to the Xtraction deployment, ensuring only authorised users have authenticated access. Review Xtraction access logs for anomalous file access requests or redirect activity that may indicate exploitation prior to patching. Implement network segmentation to isolate the Xtraction server from other critical systems where possible. Conduct periodic penetration testing against Xtraction and similar reporting platforms to identify exploitable weaknesses before they are disclosed publicly.
Ivanti Security Advisory: hub.ivanti.com/s/article/Security-Advisory-Ivanti-Xtraction-CVE-2026-14902-CVE-2026-14903. CVEs: CVE-2026-14902, CVE-2026-14903.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




