CVE-2026-45170

Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17
References
Link Resource
https://docs.cyberark.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:paloaltonetworks:idira_privilege_cloud_connector:*:*:*:*:*:*:*:*

History

23 Jun 2026, 20:16

Type Values Removed Values Added
Summary (en) Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 (en) Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17

23 Jun 2026, 14:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Paloaltonetworks
Paloaltonetworks idira Privilege Cloud Connector
References () https://docs.cyberark.com/ - () https://docs.cyberark.com/ - Product
CPE cpe:2.3:a:paloaltonetworks:idira_privilege_cloud_connector:*:*:*:*:*:*:*:*

12 Jun 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 02:16

Updated : 2026-06-23 20:16


NVD link : CVE-2026-45170

Mitre link : CVE-2026-45170

CVE.ORG link : CVE-2026-45170


JSON object : View

Products Affected

paloaltonetworks

  • idira_privilege_cloud_connector
CWE
CWE-295

Improper Certificate Validation