CVE-2026-45175

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:paloaltonetworks:idira_endpoint_privilege_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

22 Jun 2026, 20:28

Type Values Removed Values Added
First Time Apple macos
Linux
Paloaltonetworks
Apple
Linux linux Kernel
Microsoft windows
Paloaltonetworks idira Endpoint Privilege Manager
Microsoft
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:idira_endpoint_privilege_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
References () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-linux.htm#Version2650control - () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-linux.htm#Version2650control - Release Notes
References () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-macos.htm#Version2650 - () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-macos.htm#Version2650 - Release Notes
References () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-windows.htm#Version2650 - () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-windows.htm#Version2650 - Release Notes

11 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-11 20:16

Updated : 2026-06-22 20:28


NVD link : CVE-2026-45175

Mitre link : CVE-2026-45175

CVE.ORG link : CVE-2026-45175


JSON object : View

Products Affected

paloaltonetworks

  • idira_endpoint_privilege_manager

microsoft

  • windows

apple

  • macos

linux

  • linux_kernel
CWE
CWE-295

Improper Certificate Validation