CVE-2026-2914
CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs
Severity
High 8.5
CVSS 4.0
Exploited
Not listed
EPSS
0.001
4.4th percentile
Discovered by
Third party
Published by the vendor
Published
Feb 25, 2026
Assigned by palo_alto
Description
CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (1)
- CyberArk Software, a Palo Alto Networks Company · Endpoint Privilege Manager Agent
Credit
CyberArk Software, a Palo Alto Networks Company thanks Christophe Rieunier - CERT La Poste for discovering this issue.