CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs
References
| Link | Resource |
|---|---|
| https://docs.cyberark.com/epm/latest/en/content/release%20notes/release-notes.htm | Release Notes |
| https://www.cyberark.com/product-security/ | Permissions Required Vendor Advisory |
Configurations
History
27 Feb 2026, 18:58
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| References | () https://docs.cyberark.com/epm/latest/en/content/release%20notes/release-notes.htm - Release Notes | |
| References | () https://www.cyberark.com/product-security/ - Permissions Required, Vendor Advisory | |
| CPE | cpe:2.3:a:cyberark:endpoint_privilege_manager:*:*:*:*:*:*:*:* | |
| First Time |
Cyberark endpoint Privilege Manager
Cyberark |
26 Feb 2026, 22:20
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-269 |
25 Feb 2026, 02:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-25 02:16
Updated : 2026-02-27 18:58
NVD link : CVE-2026-2914
Mitre link : CVE-2026-2914
CVE.ORG link : CVE-2026-2914
JSON object : View
Products Affected
cyberark
- endpoint_privilege_manager
CWE
CWE-269
Improper Privilege Management
