CVE-2026-45169

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paloaltonetworks:idira_privileged_access_manager_vault:*:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:idira_privileged_access_manager_vault:*:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:idira_privileged_access_manager_vault:*:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:idira_privileged_access_manager_vault:*:*:*:*:*:*:*:*

History

07 Jul 2026, 15:22

Type Values Removed Values Added
CPE cpe:2.3:a:paloaltonetworks:idira_privileged_access_manager_vault:*:*:*:*:*:*:*:*
First Time Paloaltonetworks
Paloaltonetworks idira Privileged Access Manager Vault
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.6
References () https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-0-8.htm - () https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-0-8.htm - Release Notes, Vendor Advisory
References () https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-2-7.htm - () https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-2-7.htm - Release Notes, Vendor Advisory
References () https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-6-vault.htm#14.6.5 - () https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-6-vault.htm#14.6.5 - Release Notes, Vendor Advisory
References () https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew15-0-vault.htm#15.0.3 - () https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew15-0-vault.htm#15.0.3 - Release Notes, Vendor Advisory

12 Jun 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 05:16

Updated : 2026-07-07 15:22


NVD link : CVE-2026-45169

Mitre link : CVE-2026-45169

CVE.ORG link : CVE-2026-45169


JSON object : View

Products Affected

paloaltonetworks

  • idira_privileged_access_manager_vault
CWE
CWE-400

Uncontrolled Resource Consumption