CyberArk Idira Endpoint Privilege Manager是美国CyberArk公司的一个终端权限管理代理。 CyberArk Idira Endpoint Privilege Manager 26.5之前版本存在安全漏洞,该漏洞源于高权限代理组件中访问控制不当,可能导致本地低权限攻击者通过操纵内部通信机制或文件操作,在特定情况下绕过权限限制并以提升的权限执行未经授权的本地操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CyberArk Software, a Palo Alto Networks Company | Idira Endpoint Privilege Manager | 26.0< 26.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CyberArk Software, a Palo Alto Networks Company | Idira Endpoint Privilege Manager | 26.0 ~ 26.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45171 | Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Inpu | |
| CVE-2026-45172 | Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper | |
| CVE-2026-45175 | Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypa | |
| CVE-2026-45173 | Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validati | |
| CVE-2026-45177 | Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism | |
| CVE-2026-45174 | Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initializat | |
| CVE-2026-45178 | Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints |
No comments yet