CVE-2026-7431 Details
Description
An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.
A vulnerability in Ivanti Secure Access Client for Windows, in versions prior to 22.8R6, allows local authenticated users to read or alter sensitive log information. This issue arises from an incorrect permission assignment on a critical resource, which inadvertently grants write access to a shared memory section.
Users are advised to update to Ivanti Secure Access Client version 22.8R6. For those using Ivanti Connect Secure, ensure compatibility with versions 25.1.1.0, 22.8R2.3, or 22.7R2.12. Ivanti Policy Secure users should update to version 22.7R1.12, and those using Ivanti Neurons for ZTNA should update to version 22.8R1.10.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Secure-Access-Client-CVE-2026-7431-CVE-2026-7432?language=en_US | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti secure access client | <= 22.7 22.8 - 22.8 r1 22.8 r2 22.8 r3 22.8 r4 22.8 r5 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | ivanti |