Vulnerability Description
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Paloaltonetworks | Idira Secrets Manager | >= 13.0, < 13.8.1 |
| Paloaltonetworks | Idira Secrets Manager Credential Providers | >= 14.0, < 14.2.6 |
Related Weaknesses (CWE)
References
- https://docs.cyberark.com/credential-providers/latest/en/content/landingpages/cpRelease Notes
- https://docs.cyberark.com/secrets-manager-sh/13.9/en/content/enterprise/releasenRelease Notes
FAQ
What is CVE-2026-45178?
CVE-2026-45178 is a vulnerability with a CVSS score of 8.1 (HIGH). Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentia...
How severe is CVE-2026-45178?
CVE-2026-45178 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45178?
Check the references section above for vendor advisories and patch information. Affected products include: Paloaltonetworks Idira Secrets Manager, Paloaltonetworks Idira Secrets Manager Credential Providers.