CVE-2026-2914

CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs

Severity
High 8.5
CVSS 4.0
Exploited
Not listed
EPSS
0.001
4.4th percentile
Discovered by
Third party
Published by the vendor
Published
Feb 25, 2026
Assigned by palo_alto

Description

CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • CyberArk Software, a Palo Alto Networks Company · Endpoint Privilege Manager Agent

Credit

CyberArk Software, a Palo Alto Networks Company thanks Christophe Rieunier - CERT La Poste for discovering this issue.