CVE-2025-13762

Client-Side Denial of Service Condition in SWS Extension prior to version 2.2.30305

Severity
Medium 4.8
CVSS 4.0
Exploited
Not listed
EPSS
0.001
3.8th percentile
Discovered by
Vendor
Vendor-published field
Published
Nov 27, 2025
Assigned by govtech csg

Description

Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: before 2.2.30305.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by
Palo Alto Networks CyberArk Identity Identity / IAM / MFA affected-vendor
Vendor-reported products (1)
  • CyberArk · CyberArk Secure Web Sessions Extension

Credit

Benjamen Lim

Vendor remediation

Update SWS extension to v2.2.30305 or newer

Something wrong here?