Junglewise Threat Intelligence

CVE-2026-7431: Ivanti Secure Access Client incorrect permission assignment in shared memory

CVE-2026-7431 · Severity: medium · CVSS 4.4 · Published 2026-05-12

Technologies: Ivanti Secure Access Client. Vendors: Ivanti.

Executive brief

Ivanti Secure Access Client is a software application used by employees to securely connect to corporate networks and resources. A security flaw in this client allows a person who already has a standard user account on a computer to access or change sensitive internal log files. This could allow an unauthorized user to view private connection details or tamper with system records to hide their activities.

Technical details

A vulnerability classified as Incorrect Permission Assignment (CWE-732) exists in the Ivanti Secure Access Client for Windows. The flaw stems from improper access controls on a shared memory section used by the application. A local, authenticated attacker with low privileges can exploit this by gaining write access to the shared memory, enabling them to read or modify sensitive log data. This could lead to information disclosure or the integrity of system logs being compromised. The issue is resolved in version 22.8R6.

Affected products

  • Ivanti Secure Access Client before 22.8R6

Timeline

  • 2026-05-12: advisory: Vendor advisory published by Ivanti
  • 2026-05-12: disclosed: CVE-2026-7431 published to NVD

References

Related threats