
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7432 is a race condition vulnerability in Ivanti Secure Access Client that allows a locally authenticated user to escalate privileges to SYSTEM level. It affects all versions of Ivanti Secure Access Client before 22.8R6, including the 22.8 release line up through R5 and all prior versions through 22.7. The vulnerability was published on May 12, 2026, with a patch made available in version 22.8R6. It carries a CVSS v3.1 base score of 7.8 (High) per the GitHub Advisory Database, or 7.0 (High) per NVD scoring (GitHub Advisory, Ivanti Advisory).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization), commonly known as a race condition. A timing window exists in which a shared resource within the Ivanti Secure Access Client can be modified by a concurrent code sequence, allowing a low-privileged local user to manipulate the resource before it is consumed by a higher-privileged process. Exploitation requires local authentication and low privileges, but no user interaction, and the attack complexity is rated as either Low (GHSA) or High (NVD) depending on the scoring source. The vulnerability is also associated with CAPEC-26 (Leveraging Race Conditions) and CAPEC-29 (TOCTOU Race Conditions) (GitHub Advisory, Ivanti Advisory).
Successful exploitation allows a locally authenticated attacker to escalate their privileges to SYSTEM level, granting complete control over the affected Windows endpoint. This results in high impact to confidentiality, integrity, and availability — an attacker with SYSTEM privileges can access all data on the system, modify or destroy files, install malware, disable security controls, and potentially use the compromised host as a pivot point for lateral movement within the network (GitHub Advisory, Ivanti Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.027–0.03%, placing it in a low percentile for near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and a valid low-privileged account, which limits the attack surface compared to remote vulnerabilities.
Ivanti has released a patch in Ivanti Secure Access Client version 22.8R6, which resolves this vulnerability. Organizations should upgrade to version 22.8R6 or later as the primary remediation step. As interim measures, restrict local user access on systems running vulnerable versions, enforce the principle of least privilege, and monitor for suspicious privilege escalation activity on affected endpoints. Detection is supported via Nessus plugin ID 314681 (Ivanti Advisory, GitHub Advisory).
The vulnerability was covered by several cybersecurity news outlets and threat intelligence aggregators shortly after disclosure on May 12, 2026, including CyberSecurityNews and SecureReading, as part of broader coverage of Ivanti's May 2026 patch release addressing multiple products (CyberSecurityNews). Government cybersecurity agencies including the Canadian Centre for Cyber Security (CCCS) and Belgium's CCB issued advisories recommending prompt patching (CCCS Advisory, CCB Advisory). No notable researcher commentary or significant social media discussion specific to this CVE has been identified beyond routine vulnerability tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."