CVE 8.5 HIGH

Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes_CVE-2026-45175

8.5 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Amber

Description

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19

AI Analysis

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes, allowing a local attacker to potentially bypass security controls or cryptographic validations and execute unauthorized operations.

Basic Information

ID CVE-2026-45175
Source palo_alto
Published Jun 11, 2026 at 18:57

Affected Product

Vendor CyberArk Software, a Palo Alto Networks Company
Product Idira Endpoint Privilege Manager
Version 26.0
Affected Versions CyberArk Software, a Palo Alto Networks Company Idira Endpoint Privilege Manager 26.0

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor CyberArk Software, a Palo Alto Networks Company
Product Idira Endpoint Privilege Manager Agent
Version < 26.5

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.