← Vulnerability feed

Vulnerability record · CVE-2026-7432 · published 12 May 2026

CVE-2026-7432: Ivanti secure access client race condition vulnerability

Ivanti · Secure Access Client

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

7.0 CVSS 3.1 High EPSS 0.38% · top 71.1% CWE-362 · Race condition
7.0CVSS 3.1 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-7432 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-8992Ivanti secure access client improper certificate validation vulnerabilityAn improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arb…EPSS 1.2%7.8CVE-2025-22454Ivanti secure access client incorrect permission assignment vulnerabilityInsufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privilege…EPSS 0.30%7.8CVE-2024-37398Ivanti secure access client vulnerabilityInsufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.EPSS 0.32%7.8CVE-2024-7571Ivanti secure access client vulnerabilityIncorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.EPSS 0.26%7.8CVE-2023-38042Ivanti secure access client execution with unnecessary privileges vulnerabilityA local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.EPSS 0.34%7.8CVE-2023-34298Ivanti pulse secure desktop client path traversal vulnerabilityPulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate …EPSS 0.97%7.8CVE-2023-38543Ivanti secure access client allocation without limits vulnerabilityA vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to explo…EPSS 0.37%7.8CVE-2023-41718Ivanti secure access client incorrect default permissions vulnerabilityWhen a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2026-7432), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.