Junglewise Threat Intelligence

CVE-2026-7432: Ivanti Secure Access Client race condition privilege escalation

CVE-2026-7432 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Ivanti Secure Access Client. Vendors: Ivanti.

Executive brief

A vulnerability in the Ivanti Secure Access Client, a tool used for secure remote connectivity, could allow a user already logged into a Windows computer to gain full administrative (SYSTEM) control. This type of flaw is typically used by attackers who have already gained a foothold on a machine to deepen their access and disable security protections. Organizations should update the client software to version 22.8R6 or later to prevent this privilege escalation.

Technical details

A race condition (CWE-362) exists in the Ivanti Secure Access Client for Windows prior to version 22.8R6. The vulnerability occurs during concurrent execution using shared resources with improper synchronization, allowing a locally authenticated attacker with low privileges to exploit a timing window to execute code with SYSTEM-level authority. The attack requires local access to the target machine but no user interaction. Ivanti has released version 22.8R6 to address this issue.

Affected products

  • Ivanti Secure Access Client before 22.8R6

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory
  • 2026-05-12: patched

References

Related threats