7.8

CVE-2026-45176

Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation Manipulation

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paloaltonetworks ≫ Idira Endpoint Privilege Manager Version < 26.5.0
   Apple ≫ macOS Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.025
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@paloaltonetworks.com 8.9 0 0
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-windows.htm#Version2650
Release Notes
https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-macos.htm#Version2650
Release Notes
https://docs.cyberark.com/epm/latest/en/content/release%20notes/rn-os-linux.htm#Version2650
Release Notes