Skip to main content
CVE Vulnerability Database

CVE-2026-7432: Ivanti Secure Access Client Privilege Escalation

CVE-2026-7432 is a race condition vulnerability in Ivanti Secure Access Client that allows locally authenticated users to escalate privileges to SYSTEM. This article covers technical details, affected versions, and mitigations.

Published:

CVE-2026-7432 Overview

CVE-2026-7432 is a race condition vulnerability in Ivanti Secure Access Client versions prior to 22.8R6 running on Microsoft Windows. The flaw allows a locally authenticated user to escalate privileges to SYSTEM, the highest privilege level on Windows. The weakness is classified under [CWE-362] (Concurrent Execution using Shared Resource with Improper Synchronization). Exploitation requires local access and high attack complexity, but successful exploitation grants full control over the affected host. Ivanti disclosed the issue in its May 2026 security advisory alongside CVE-2026-7431.

Critical Impact

A locally authenticated attacker can win a timing race in the Ivanti Secure Access Client to escalate from a standard user to SYSTEM, gaining complete control of the Windows endpoint.

Affected Products

  • Ivanti Secure Access Client versions prior to 22.8R6 on Microsoft Windows
  • Ivanti Secure Access Client 22.8, 22.8R1, 22.8R2, 22.8R3, 22.8R4, and 22.8R5
  • Microsoft Windows endpoints running the affected client

Discovery Timeline

  • 2026-05-12 - CVE-2026-7432 published to NVD
  • 2026-05-12 - Last updated in NVD database

Technical Details for CVE-2026-7432

Vulnerability Analysis

The vulnerability is a race condition in the Ivanti Secure Access Client, a VPN client commonly deployed on enterprise Windows endpoints. The client runs privileged service components that interact with user-controlled resources during connection and configuration operations. An attacker who can execute code as a standard local user can manipulate shared resources between the time the privileged service validates them and the time it acts on them.

Because the client service runs as SYSTEM, winning the race yields full local privilege escalation. The attack vector is local and the attack complexity is high, reflecting the timing precision required. Exploitation does not require user interaction. No public exploit or proof of concept is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Root Cause

The root cause is improper synchronization between concurrent operations performed by the Ivanti Secure Access Client. A privileged component validates or accesses a resource and then operates on it later without ensuring atomicity. This Time-of-Check to Time-of-Use (TOCTOU) pattern is the canonical form of [CWE-362] and frequently appears in Windows endpoint agents that handle files, registry keys, or named objects on behalf of unprivileged callers.

Attack Vector

A local authenticated user runs code that repeatedly triggers the privileged client operation while concurrently swapping or modifying the target resource. When the timing aligns, the privileged service acts on attacker-controlled data, producing a primitive such as arbitrary file write, symbolic link follow, or code execution under the SYSTEM account. Refer to the Ivanti May 2026 Security Advisory for vendor-provided technical context.

Detection Methods for CVE-2026-7432

Indicators of Compromise

  • Unexpected child processes spawned by Ivanti Secure Access Client service binaries running as SYSTEM
  • New or modified files in directories used by the Ivanti client where the writing process is SYSTEM but the originating user context is a standard account
  • Repeated, rapid file or registry operations targeting Ivanti client paths from a non-administrative process

Detection Strategies

  • Monitor for privilege escalation patterns where a standard user process is followed by SYSTEM-level activity tied to the Ivanti Secure Access Client process tree
  • Alert on symbolic link, hard link, or junction creation pointing into directories owned by the Ivanti client service
  • Hunt for high-frequency open, rename, or delete operations on Ivanti client files originating from non-elevated processes, which can indicate race window probing

Monitoring Recommendations

  • Enable Windows process creation auditing (Event ID 4688) with command-line logging on endpoints running the Ivanti Secure Access Client
  • Forward endpoint telemetry, including file, registry, and process events, to a centralized analytics platform for correlation
  • Track the installed version of Ivanti Secure Access Client across the fleet and flag any host still running a build older than 22.8R6

How to Mitigate CVE-2026-7432

Immediate Actions Required

  • Upgrade Ivanti Secure Access Client to version 22.8R6 or later on all Windows endpoints
  • Inventory endpoints to identify any host running affected versions 22.8 through 22.8R5
  • Restrict local interactive logon on high-value endpoints to reduce the population of users who could attempt local exploitation

Patch Information

Ivanti has released a fixed build in version 22.8R6 that addresses CVE-2026-7432. Customers should apply the update following the guidance in the Ivanti May 2026 Security Advisory, which also addresses CVE-2026-7431. Prioritize patching on endpoints accessible to standard users or shared workstations.

Workarounds

  • No vendor-supplied workaround is documented; applying the 22.8R6 update is the supported remediation
  • As a compensating control, limit local user privileges and enforce application allowlisting to constrain execution of unauthorized binaries
  • Monitor Ivanti client service activity for anomalous privileged operations until patching is complete

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.