CyberArk Idira Secrets Manager SaaS Edge是美国CyberArk公司的一个分布式机密访问节点组件。 CyberArk Idira Secrets Manager SaaS Edge 1.8之前版本存在访问控制错误漏洞,该漏洞源于内部身份验证组件中访问控制不当,可能导致远程未经身份验证的攻击者通过提交特制请求,在特定情况下操纵内部验证机制,绕过身份验证并获取访问令牌。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CyberArk Software, a Palo Alto Networks Company | Conjur Cloud (Edge Finding only) | 1.0< 1.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CyberArk Software, a Palo Alto Networks Company | Conjur Cloud (Edge Finding only) | 1.0 ~ 1.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45171 | Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Inpu | |
| CVE-2026-45172 | Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper | |
| CVE-2026-45175 | Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypa | |
| CVE-2026-45173 | Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validati | |
| CVE-2026-45174 | Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initializat | |
| CVE-2026-45178 | Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints | |
| CVE-2026-45176 | Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communicat |
No comments yet