Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cyberark
Cyberark conjur Enterprise |
|
| Vendors & Products |
Cyberark
Cyberark conjur Enterprise |
Thu, 11 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20 | |
| Title | Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints | |
| First Time appeared |
Cyberark Software A Palo Alto Networks Company
Cyberark Software A Palo Alto Networks Company conjur Enterprise |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:cyberark_software_a_palo_alto_networks_company:conjur_enterprise:*:*:central_credential_provider_ccp_:*:*:*:*:* cpe:2.3:a:cyberark_software_a_palo_alto_networks_company:conjur_enterprise:*:*:credential_provider_cp_:*:*:*:*:* cpe:2.3:a:cyberark_software_a_palo_alto_networks_company:conjur_enterprise:*:*:idira_secrets_manager:*:*:*:*:* cpe:2.3:a:cyberark_software_a_palo_alto_networks_company:conjur_enterprise:*:*:z_os_credential_provider:*:*:*:*:* |
|
| Vendors & Products |
Cyberark Software A Palo Alto Networks Company
Cyberark Software A Palo Alto Networks Company conjur Enterprise |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2026-06-11T19:04:56.256Z
Reserved: 2026-05-08T23:01:00.502Z
Link: CVE-2026-45178
Updated: 2026-06-11T19:04:50.308Z
Status : Awaiting Analysis
Published: 2026-06-11T19:16:42.040
Modified: 2026-06-11T20:56:29.653
Link: CVE-2026-45178
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:22:13Z