CVE-2026-45171
HIGH WAF: High
CVSS 8.8
Published: 2026-06-11
CWE-22
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18
WAF Coverage Analysis
Path Traversal
High WAF Coverage
OWASP: A01:2021 Broken Access Control
930xxx - Local File Inclusion
Affected Software
| Vendor | Product | Version |
|---|---|---|
| paloaltonetworks | idira_privileged_session_manager | 14.0 - 14.0.5 |
| paloaltonetworks | idira_privileged_session_manager | 14.2 - 14.2.5 |
| paloaltonetworks | idira_privileged_session_manager | 14.6 - 14.6.3 |
| paloaltonetworks | idira_privileged_session_manager | 15.0 - 15.0.3 |
References
- docs.cyberark.com (Release Notes)
- docs.cyberark.com (Release Notes)
- docs.cyberark.com (Release Notes)
- docs.cyberark.com (Release Notes)