A high-severity access-control bug in a service-management platform is a reminder that a valid login is not the same as a valid authority boundary.
A high-severity authorization bug in Ivanti Neurons for ITSM shows how one broken privilege boundary can put an entire service-management control plane at risk.