CVE-2026-7431
MEDIUMIvanti Secure Access Client - Incorrect Permission Assignment for Critical Resource
Title source: ruleDescription
An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.
References (1)
Core 1
Scores
CVSS v3
4.4
EPSS
0.0004
EPSS Percentile
13.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-732
Status
published
Products (3)
ivanti/Secure Access Client
22.8R6
ivanti/secure_access_client
22.8 (6 CPE variants)
ivanti/secure_access_client
< 22.7
Published
May 12, 2026
Tracked Since
May 12, 2026