Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CyberArk Software, a Palo Alto Networks Company — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting CyberArk Software, a Palo Alto Networks Company. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page catalogs Common Weakness Enumerations (CWE) associated with CyberArk Software, a Palo Alto Networks Company. It aggregates vulnerability data related to specific product configurations and software defects within the vendor’s identity and access management ecosystem. The collection includes reported security issues spanning from early implementations through recent releases, ensuring a comprehensive historical view of the vendor’s security posture over time. Here, you can track a vendor's advisories to stay informed about newly disclosed risks and ongoing remediation efforts. You may also understand a weakness class by examining how similar flaws manifest across different products or versions within the CyberArk portfolio. Furthermore, this resource allows you to look up a product's vulnerability history, providing context on the frequency and severity of past incidents to aid in risk assessment and prioritization. The data is organized to facilitate efficient review for security professionals, auditors, and compliance officers who need to evaluate the impact of specific weaknesses on their environments. By consolidating this information, the page supports informed decision-making regarding patch management, architectural reviews, and third-party risk management. The scope covers a wide range of vulnerability types, including authentication bypasses, privilege escalation, and insecure data storage, reflecting the complex nature of identity governance solutions.

CVE IDTitleCVSSSeverityPublished
CVE-2026-45169 Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing — PAM SH VaultCWE-400--2026-06-12
CVE-2026-45170 Idira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to Incomplete TLS Certificate Validation — Vendor PAMCWE-295--2026-06-12
CVE-2026-45171 Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input Validation — Privileged Session Manager, VaultCWE-22--2026-06-11
CVE-2026-45172 Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special Elements used in an OS Command — PAM Self-Hosted, Privilege CloudCWE-78--2026-06-11
CVE-2026-45173 Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure — Identity Browser ExtensionsCWE-346--2026-06-11
CVE-2026-45174 Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initialization — Idira Endpoint Privilege ManagerCWE-404--2026-06-11
CVE-2026-45175 Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes — Idira Endpoint Privilege ManagerCWE-295--2026-06-11
CVE-2026-45176 Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation Manipulation — Idira Endpoint Privilege ManagerCWE-269--2026-06-11
CVE-2026-45177 Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism — Conjur Cloud (Edge Finding only)CWE-284--2026-06-11
CVE-2026-45178 Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints — Conjur EnterpriseCWE-284--2026-06-11
CVE-2026-2914 CyberArk Endpoint Privilege Manager Agent 安全漏洞 — Endpoint Privilege Manager Agent 8.8AIHighAI2026-02-25

This page lists every published CVE security advisory associated with CyberArk Software, a Palo Alto Networks Company. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.