CVE-2023-28126: Ivanti Avalanche

Medium severity, CVSS 5.9. EPSS: 66.7% chance of exploitation in the next 30 days.

An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.

Affected products

  • Ivanti Avalanche: up to and including 6.3.4.153

Published 2023-05-09. Last modified 2026-06-17.