vciy

CVEs we hold for Cyberark

Records whose assigning authority named Cyberark as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-45178Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster EndpointsCyberArk Software, a Palo Alto Networks Company Conjur…
CVE-2026-45177Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanismCyberArk Software, a Palo Alto Networks Company Conjur…
CVE-2026-45176Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation…CyberArk Software, a Palo Alto Networks Company Idira…
CVE-2026-45175Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent…CyberArk Software, a Palo Alto Networks Company Idira…
CVE-2026-45174Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon InitializationCyberArk Software, a Palo Alto Networks Company Idira…
CVE-2026-45173Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation FailureCyberArk Software, a Palo Alto Networks Company Identity…
CVE-2026-45172Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special…CyberArk Software, a Palo Alto Networks Company PAM…
CVE-2026-45171Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input ValidationCyberArk Software, a Palo Alto Networks Company Privileged…
CVE-2026-45170Idira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to Incomplete TLS Certificate ValidationCyberArk Software, a Palo Alto Networks Company Vendor PAM
CVE-2026-45169Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input ProcessingCyberArk Software, a Palo Alto Networks Company PAM SH Vault
CVE-2026-2914no title heldCyberArk Software, a Palo Alto Networks Company Endpoint…
CVE-2025-49831Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to IAM Authenticator Bypass via…cyberark conjur
CVE-2025-49830Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to path traversal and file…cyberark conjur
CVE-2025-49829Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) missing validationscyberark conjur
CVE-2025-49828Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Remote Code Executioncyberark conjur
CVE-2025-49827Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticatorcyberark conjur
CVE-2025-46382no title heldCyberArk IDP
CVE-2025-22274HTML injection in CyberArk Endpoint Privilege ManagerCyberArk Endpoint Privilege Manager
CVE-2025-22273Lack of rate-limiting in password change mechanism in CyberArk Endpoint Privilege ManagerCyberArk Endpoint Privilege Manager
CVE-2025-22272Self Reflected XSS in CyberArk Endpoint Privilege ManagerCyberArk Endpoint Privilege Manager
CVE-2025-22271IP Spoofing in CyberArk Endpoint Privilege ManagerCyberArk Endpoint Privilege Manager
CVE-2025-22270Stored XSS in CyberArk Endpoint Privilege ManagerCyberArk Endpoint Privilege Manager
CVE-2025-13762Client-Side Denial of Service Condition in SWS Extension prior to version 2.2.30305CyberArk Secure Web Sessions Extension
CVE-2024-57967no title heldCyberArk Privileged Access Manager
CVE-2024-54840no title heldCyberArk Privileged Access Manager
CVE-2024-42340CyberArk - CWE-602: Client-Side Enforcement of Server-Side SecurityCyberArk Identity Management
CVE-2024-42339CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCyberArk Identity Management
CVE-2024-42338CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCyberArk Identity Management
CVE-2024-42337CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized ActorCyberArk Identity Management
CVE-2022-22700no title heldn/a CyberArk Identity
CVE-2021-37151no title heldCyberArk Identity
CVE-2020-4062Improper Access Control in Conjur OSS Helm ChartCyberArk Conjur OSS Helm Chart

32 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.