CVE-2026-45177

Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism

Severity
Critical 9.1
CVSS 4.0
Exploited
Not listed
EPSS
0.005
42.1th percentile
Discovered by
Vendor
Vendor-published field
Published
Jun 11, 2026
Assigned by palo_alto

Description

Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20

Weakness: CWE-284

Affected products

Vendor Product Category Matched by
Palo Alto Networks CyberArk Conjur Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • CyberArk Software, a Palo Alto Networks Company · Conjur Cloud (Edge Finding only)

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue

Something wrong here?