Bg ShapeBg Shape
THREAT INTELLIGENCE

High and Medium Vulnerabilities Patched in Ivanti Xtraction - 15th July 2026

Affected Environment

Ivanti Xtraction versions 2026.2 and prior, across all supported deployment types. Fixed in version 2026.2.1, available via the Ivanti Licensing Server (ILS).

Threat Overview

Ivanti disclosed two vulnerabilities in Xtraction, its data visualisation and reporting platform. The more severe flaw, CVE-2026-14903 (CVSS 7.7), is a path traversal vulnerability allowing a remote authenticated attacker to read arbitrary files located outside the web root on the underlying server. The second vulnerability, CVE-2026-14902 (CVSS 4.0), is an open redirect that allows a remote unauthenticated attacker to redirect users to arbitrary external URLs, which can be leveraged in phishing and credential harvesting attacks.

Exposure Timeline

Advisory published 15 July 2026. No active exploitation confirmed at time of publication. Fixed version 2026.2.1 is available immediately via the Ivanti Licensing Server. The standard recommended remediation window is ten working days.

Attack Surface

CVE-2026-14903 requires authenticated access to Xtraction. CVE-2026-14902 is exploitable by unauthenticated attackers who can craft and distribute malicious redirect URLs. Any internet-accessible Xtraction deployment is exposed to the open redirect, and any authenticated user with access to the platform can potentially exploit the path traversal.

Operational Impact

CVE-2026-14903 allows a remote authenticated attacker to read arbitrary files outside the Xtraction web root. Depending on server configuration, this could expose sensitive files including configuration files, credentials, internal application data, and potentially operating system files accessible to the web application process. CVE-2026-14902 allows unauthenticated attackers to abuse the platform's redirect mechanism to send users to attacker-controlled sites, facilitating phishing, credential theft, and social engineering attacks that leverage the legitimacy of the Xtraction domain.

Strategic Impact

Risk is rated High across all government and business entity sizes. Xtraction is commonly deployed in environments that aggregate data from IT service management and business intelligence platforms, meaning the data accessible via path traversal could include sensitive operational or financial information. The open redirect risk is amplified in organisations where Xtraction is a trusted and recognised internal tool, increasing the likelihood that users will follow redirect links without suspicion.

Required Mitigation

Upgrade Ivanti Xtraction to version 2026.2.1 immediately via the Ivanti Licensing Server. No workarounds are documented for either vulnerability; patching is the only remediation. Establish and maintain a documented vulnerability management and remediation process to ensure future advisories are actioned within the ten-working-day window. Conduct automated vulnerability scans of both internal and externally-exposed assets on a regular basis.

Incident Response Guidance

Apply the Principle of Least Privilege to the Xtraction deployment, ensuring only authorised users have authenticated access. Review Xtraction access logs for anomalous file access requests or redirect activity that may indicate exploitation prior to patching. Implement network segmentation to isolate the Xtraction server from other critical systems where possible. Conduct periodic penetration testing against Xtraction and similar reporting platforms to identify exploitable weaknesses before they are disclosed publicly.

References

Ivanti Security Advisory: hub.ivanti.com/s/article/Security-Advisory-Ivanti-Xtraction-CVE-2026-14902-CVE-2026-14903. CVEs: CVE-2026-14902, CVE-2026-14903.

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image