CVE-2026-45177
Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism
Severity
Critical 9.1
CVSS 4.0
Exploited
Not listed
EPSS
0.005
42.1th percentile
Discovered by
Vendor
Vendor-published field
Published
Jun 11, 2026
Assigned by palo_alto
Description
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20
Weakness: CWE-284
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | CyberArk Conjur | Identity / IAM / MFA | cna-assigner |
Vendor-reported products (1)
- CyberArk Software, a Palo Alto Networks Company · Conjur Cloud (Edge Finding only)
Credit
Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue