PT-2026-40038 · Ivanti · Secure Access Client

CVE-2026-7431

·

Published

2026-05-12

·

Updated

2026-05-15

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ivanti Secure Access Client versions prior to 22.8R6
Description An incorrect permission assignment for a critical resource allows a local authenticated user to read or modify sensitive log data. This is possible through write access to a shared memory section, which is a block of memory that can be accessed by multiple programs to communicate or share data.
Recommendations Update to version 22.8R6 or later.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7431

Affected Products

Secure Access Client