Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21
References
Configurations
Configuration 1 (hide)
| AND |
|
History
22 Jun 2026, 18:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:paloaltonetworks:idira_identity_browser_extension:*:*:*:*:*:-:*:* cpe:2.3:a:google:chrome:-:*:*:*:*:*:*:* cpe:2.3:a:mozilla:firefox:-:*:*:*:*:*:*:* cpe:2.3:a:microsoft:edge_chromium:-:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| First Time |
Mozilla
Microsoft edge Chromium Paloaltonetworks Paloaltonetworks idira Identity Browser Extension Google chrome Microsoft Mozilla firefox |
|
| References | () https://docs.cyberark.com/find-identity-administration-docs/latest/en/content/getstarted/identity-new-doc-location.htm - Product |
11 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-11 22:16
Updated : 2026-06-22 18:34
NVD link : CVE-2026-45173
Mitre link : CVE-2026-45173
CVE.ORG link : CVE-2026-45173
JSON object : View
Products Affected
- chrome
mozilla
- firefox
paloaltonetworks
- idira_identity_browser_extension
microsoft
- edge_chromium
CWE
CWE-346
Origin Validation Error
