Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19
References
Configurations
Configuration 1 (hide)
| AND |
|
History
22 Jun 2026, 20:28
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apple macos
Linux Paloaltonetworks Apple Linux linux Kernel Microsoft windows Paloaltonetworks idira Endpoint Privilege Manager Microsoft |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:idira_endpoint_privilege_manager:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| References | () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-linux.htm#Version2650control - Release Notes | |
| References | () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-macos.htm#Version2650 - Release Notes | |
| References | () https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-windows.htm#Version2650 - Release Notes |
11 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-11 20:16
Updated : 2026-06-22 20:28
NVD link : CVE-2026-45175
Mitre link : CVE-2026-45175
CVE.ORG link : CVE-2026-45175
JSON object : View
Products Affected
paloaltonetworks
- idira_endpoint_privilege_manager
microsoft
- windows
apple
- macos
linux
- linux_kernel
CWE
CWE-295
Improper Certificate Validation
