CVE-2026-45171

HIGH WAF: High
CVSS 8.8 Published: 2026-06-11
CWE-22

Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18

WAF Coverage Analysis

Path Traversal High WAF Coverage

OWASP: A01:2021 Broken Access Control

930xxx - Local File Inclusion

Affected Software

VendorProductVersion
paloaltonetworksidira_privileged_session_manager14.0 - 14.0.5
paloaltonetworksidira_privileged_session_manager14.2 - 14.2.5
paloaltonetworksidira_privileged_session_manager14.6 - 14.6.3
paloaltonetworksidira_privileged_session_manager15.0 - 15.0.3

References

Back to CVE Database