CyberArk Idira Secrets Manager Self-Hosted是美国CyberArk公司的一个企业级机密信息管理平台。 CyberArk Idira Secrets Manager Self-Hosted 13.8.0及之前版本存在访问控制错误漏洞,该漏洞源于内部集群端点中访问控制不当,可能导致拥有标准节点级凭据的远程经过身份验证的攻击者利用这些端点检索未经授权的机密或造成拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CyberArk Software, a Palo Alto Networks Company | Conjur Enterprise | 13.0< 13.8.1 |
affected |
14.0< 14.2.6 |
affected | ||
14.0< 14.2.6 |
affected | ||
14.0< 14.2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CyberArk Software, a Palo Alto Networks Company | Conjur Enterprise | 13.0 ~ 13.8.1 | - |
|
| CyberArk Software, a Palo Alto Networks Company | Conjur Enterprise | 14.0 ~ 14.2.6 | - |
|
| CyberArk Software, a Palo Alto Networks Company | Conjur Enterprise | 14.0 ~ 14.2.6 | - |
|
| CyberArk Software, a Palo Alto Networks Company | Conjur Enterprise | 14.0 ~ 14.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45171 | Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Inpu | |
| CVE-2026-45172 | Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper | |
| CVE-2026-45175 | Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypa | |
| CVE-2026-45173 | Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validati | |
| CVE-2026-45177 | Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism | |
| CVE-2026-45174 | Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initializat | |
| CVE-2026-45176 | Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communicat |
No comments yet