CVE-2026-45169
HIGH WAF: Medium
CVSS 8.6
Published: 2026-06-12
CWE-400
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17
WAF Coverage Analysis
Uncontrolled Resource Consumption
Medium WAF Coverage
OWASP: A05:2021 Security Misconfiguration
912xxx - DOS Protection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| paloaltonetworks | idira_privileged_access_manager_vault | 14.0 - 14.0.8 |
| paloaltonetworks | idira_privileged_access_manager_vault | 14.2 - 14.2.7 |
| paloaltonetworks | idira_privileged_access_manager_vault | 14.6 - 14.6.5 |
| paloaltonetworks | idira_privileged_access_manager_vault | 15.0 - 15.0.3 |
References
- docs.cyberark.com (Release Notes, Vendor Advisory)
- docs.cyberark.com (Release Notes, Vendor Advisory)
- docs.cyberark.com (Release Notes, Vendor Advisory)
- docs.cyberark.com (Release Notes, Vendor Advisory)