CVE-2019-7394: Ca Risk Authentication

High severity, CVSS 8.8. EPSS: 2.8% chance of exploitation in the next 30 days.

A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 7.1.x and CA Risk Authentication 9.0.x, 8.2.x, 8.1.x, 8.0.x, 3.1.x allows an authenticated attacker to gain additional privileges in some cases where an account has customized and limited privileges.

Affected products

  • Ca Risk Authentication: from 8.0, up to and including 8.2.1; version 3.1 only; version 9.0 only
  • Ca Strong Authentication: from 8.0, up to and including 8.2.1; version 7.1 only; version 9.0 only

Published 2019-05-28. Last modified 2026-06-17.