Vulnerability Description
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Idira Endpoint Privilege Manager | < 26.5.0 |
| Apple | Macos | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-linux.htm#Release Notes
- https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-macos.htm#Release Notes
- https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-windows.htRelease Notes
FAQ
What is CVE-2026-45175?
CVE-2026-45175 is a vulnerability with a CVSS score of 7.8 (HIGH). Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security co...
How severe is CVE-2026-45175?
CVE-2026-45175 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45175?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Idira Endpoint Privilege Manager, Apple Macos, Linux Linux Kernel, Microsoft Windows.