CyberArk Idira Privileged Session Manager是美国CyberArk公司的一个特权会话管理平台。 CyberArk Idira Privileged Session Manager 15.0.3之前版本、14.6.3之前版本、14.2.5之前版本和14.0.5之前版本存在路径遍历漏洞,该漏洞源于输入验证不完整和文件夹权限配置不当,可能导致经过身份验证的低权限用户执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CyberArk Software, a Palo Alto Networks Company | Privileged Session Manager, Vault | 14.0< 14.0.5 |
affected |
14.2< 14.2.5 |
affected | ||
14.6< 14.6.3 |
affected | ||
15.0< 15.0.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CyberArk Software, a Palo Alto Networks Company | Privileged Session Manager, Vault | 14.0 ~ 14.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45172 | Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper | |
| CVE-2026-45175 | Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypa | |
| CVE-2026-45173 | Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validati | |
| CVE-2026-45177 | Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism | |
| CVE-2026-45174 | Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initializat | |
| CVE-2026-45178 | Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints | |
| CVE-2026-45176 | Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communicat |
No comments yet