CVE-2026-45169

Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing

Severity
High 8.7
CVSS 4.0
Exploited
Not listed
EPSS
0.004
27.7th percentile
Discovered by
Vendor
Published by the vendor
Published
Jun 12, 2026
Assigned by palo_alto

Description

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17

Weakness: CWE-400

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • CyberArk Software, a Palo Alto Networks Company · PAM SH Vault

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue