Vulnerability Description
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Idira Endpoint Privilege Manager | < 26.5.0 |
| Apple | Macos | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-linux.htm#Release Notes
- https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-macos.htm#Release Notes
- https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-windows.htRelease Notes
FAQ
What is CVE-2026-45176?
CVE-2026-45176 is a vulnerability with a CVSS score of 7.8 (HIGH). Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulati...
How severe is CVE-2026-45176?
CVE-2026-45176 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45176?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Idira Endpoint Privilege Manager, Apple Macos, Linux Linux Kernel, Microsoft Windows.