CVE-2026-7432 Details
Description
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
A race condition vulnerability has been identified in Ivanti Secure Access Client for Windows, affecting versions through 22.8R5. This vulnerability allows a locally authenticated user to escalate privileges to the SYSTEM level.
Users are advised to update to Ivanti Secure Access Client version 22.8R6. Instructions for downloading the updated client are available on the Ivanti Download Portal. Compatible server versions for the updated client include Ivanti Connect Secure 25.1.1.0, 22.8R2.3, 22.7R2.12, Ivanti Policy Secure 22.7R1.12, and Ivanti Neurons for ZTNA 22.8R1.10.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Secure-Access-Client-CVE-2026-7431-CVE-2026-7432?language=en_US | ivanti | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | ivanti |
Affected Products
| Product | Versions |
|---|---|
| ivanti secure access client | <= 22.7 22.8 - 22.8 r1 22.8 r2 22.8 r3 22.8 r4 22.8 r5 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ivanti |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | Initial Analysis | [email protected] |
| May 12, 2026 | New CVE Received | ivanti |