CVE-2026-45177

Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism

Severity
Critical 9.1
CVSS 4.0
Exploited
Not listed
EPSS
0.005
40.3th percentile
Discovered by
Vendor
Published by the vendor
Published
Jun 11, 2026
Assigned by palo_alto

Description

Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20

Weakness: CWE-284

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • CyberArk Software, a Palo Alto Networks Company · Conjur Cloud (Edge Finding only)

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue