CVEs we hold for Cyberark
Records whose assigning authority named Cyberark as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-45178Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster EndpointsCyberArk Software, a Palo Alto Networks Company Conjur…
CVE-2026-45177Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanismCyberArk Software, a Palo Alto Networks Company Conjur…
CVE-2026-45176Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation…CyberArk Software, a Palo Alto Networks Company Idira…
CVE-2026-45175Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent…CyberArk Software, a Palo Alto Networks Company Idira…
CVE-2026-45174Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon InitializationCyberArk Software, a Palo Alto Networks Company Idira…
CVE-2026-45173Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation FailureCyberArk Software, a Palo Alto Networks Company Identity…
CVE-2026-45172Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special…CyberArk Software, a Palo Alto Networks Company PAM…
CVE-2026-45171Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input ValidationCyberArk Software, a Palo Alto Networks Company Privileged…
CVE-2026-45170Idira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to Incomplete TLS Certificate ValidationCyberArk Software, a Palo Alto Networks Company Vendor PAM
CVE-2026-45169Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input ProcessingCyberArk Software, a Palo Alto Networks Company PAM SH Vault
CVE-2025-49831Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to IAM Authenticator Bypass via…cyberark conjur
CVE-2025-49830Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to path traversal and file…cyberark conjur
CVE-2025-49829Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) missing validationscyberark conjur
CVE-2025-49828Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Remote Code Executioncyberark conjur
CVE-2025-49827Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticatorcyberark conjur
CVE-2025-22274HTML injection in CyberArk Endpoint Privilege ManagerCyberArk Endpoint Privilege Manager
CVE-2025-22273Lack of rate-limiting in password change mechanism in CyberArk Endpoint Privilege ManagerCyberArk Endpoint Privilege Manager
CVE-2025-22272Self Reflected XSS in CyberArk Endpoint Privilege ManagerCyberArk Endpoint Privilege Manager
CVE-2025-13762Client-Side Denial of Service Condition in SWS Extension prior to version 2.2.30305CyberArk Secure Web Sessions Extension
CVE-2024-42340CyberArk - CWE-602: Client-Side Enforcement of Server-Side SecurityCyberArk Identity Management
CVE-2024-42339CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCyberArk Identity Management
CVE-2024-42338CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCyberArk Identity Management
CVE-2024-42337CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCyberArk Identity Management
32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.