MEDIUM · 6.5

CVE-2026-45173

Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated u...

Vulnerability Description

Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
PaloaltonetworksIdira Identity Browser Extension>= 26.0.0, < 26.8.1
GoogleChrome-
MicrosoftEdge Chromium-
MozillaFirefox-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-45173?

CVE-2026-45173 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated u...

How severe is CVE-2026-45173?

CVE-2026-45173 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-45173?

Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Idira Identity Browser Extension, Google Chrome, Microsoft Edge Chromium, Mozilla Firefox.