← Vulnerability feed

Vulnerability record · CVE-2024-21888 · published 31 January 2024

CVE-2024-21888: Ivanti Connect Secure and Policy Secure web component privilege escalation

Ivanti · Connect Secure

The web component of Ivanti Connect Secure and Policy Secure (9.x, 22.x) has an improper privilege management flaw that lets an authenticated user elevate to administrator. Because the affected products are remote access gateways, a compromised admin account can expose the whole VPN/ZTNA estate.

8.8 CVSS 3.1 High EPSS 85% · top 0.3% CWE-269 · Improper privilege management
8.8CVSS 3.1 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityHigh CVSS (8.8) and very high EPSS (0.868) on an internet-facing remote access gateway, though no KEV listing or known exploit is documented.

What it is

The web component of Ivanti Connect Secure and Policy Secure (9.x, 22.x) has an improper privilege management flaw that lets an authenticated user elevate to administrator. Because the affected products are remote access gateways, a compromised admin account can expose the whole VPN/ZTNA estate.

Impact

An attacker with a low-privileged account gains full administrative control of the appliance, including configuration, user data and policy changes.

Attack surface

Reachable over the network through the web component (AV:N) with low privileges required (PR:L) and no user interaction (UI:N).

Exploitation

Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is very high at 0.868 (99.7th percentile), indicating elevated likelihood of exploitation.

What to do

  • Apply the Ivanti vendor advisory fix for Connect Secure and Policy Secure 9.x and 22.x immediately.
  • Restrict administrative and web UI access to trusted management networks or VPN-only paths.
  • Audit and remove unnecessary low-privileged accounts on the appliances.
  • Enable and forward appliance audit logs to a central SIEM for privilege-change monitoring.
  • Rotate credentials and review admin accounts for unauthorized changes after patching.

Detection

  • Alert on new or modified administrator accounts and role changes in Ivanti appliance logs.
  • Monitor for low-privileged sessions invoking administrative endpoints or functions in the web component.
  • Correlate web UI access from unusual source IPs with subsequent admin actions.
  • Review authentication logs for privilege escalation sequences around the same session.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-21888 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.8CVE-2025-22457Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2024-21888), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.