CVE-2026-45172

HIGH WAF: High
CVSS 8.8 Published: 2026-06-11
CWE-78

Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
paloaltonetworksidira_privileged_session_manager_for_ssh14.0 - 14.0.6
paloaltonetworksidira_privileged_session_manager_for_ssh14.2 - 14.2.5
paloaltonetworksidira_privileged_session_manager_for_ssh14.6 - 14.6.3
paloaltonetworksidira_privileged_session_manager_for_ssh15.0 - 15.0.2

References

Back to CVE Database