← All Advisories

CyberArk Endpoint Privilege Manager Agent Improper Access Control Lets a Local Low-Privilege Attacker Execute Unauthorized Actions with Elevated Privileges

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-45176

Key Details

CVECVE-2026-45176
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-06-22
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsPalo Alto Networks idira_endpoint_privilege_manager
Classified asCWE-269 (Improper Privilege Management)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto Networksidira_endpoint_privilege_manager
SubsystemsGeneral OT
SectorsMultiple

What to Know

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19 (NVD)

What to Do

Monitor Palo Alto Networks's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-45176
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-45176