CVE-2026-7431: Ivanti Secure Access Client
Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.
An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.
Affected products
- Ivanti Secure Access Client: up to and including 22.7; version 22.8 only
Published 2026-05-12. Last modified 2026-06-17.