CVE-2026-7431: Ivanti Secure Access Client

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.

Affected products

  • Ivanti Secure Access Client: up to and including 22.7; version 22.8 only

Published 2026-05-12. Last modified 2026-06-17.