Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19
Metrics
Affected Vendors & Products
References
History
Thu, 11 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19 | |
| Title | Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation Manipulation | |
| First Time appeared |
Cyberark Software A Palo Alto Networks Company
Cyberark Software A Palo Alto Networks Company idira Endpoint Privilege Manager |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:cyberark_software_a_palo_alto_networks_company:idira_endpoint_privilege_manager:*:*:linux:*:*:*:*:* cpe:2.3:a:cyberark_software_a_palo_alto_networks_company:idira_endpoint_privilege_manager:*:*:macos:*:*:*:*:* cpe:2.3:a:cyberark_software_a_palo_alto_networks_company:idira_endpoint_privilege_manager:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Cyberark Software A Palo Alto Networks Company
Cyberark Software A Palo Alto Networks Company idira Endpoint Privilege Manager |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: palo_alto
Published: 2026-06-11T18:49:00.712Z
Updated: 2026-06-11T19:02:13.450Z
Reserved: 2026-05-08T23:01:00.502Z
Link: CVE-2026-45176
Updated: 2026-06-11T19:01:49.343Z
Status : Awaiting Analysis
Published: 2026-06-11T19:16:41.757
Modified: 2026-06-11T20:56:29.653
Link: CVE-2026-45176
No data.