CVE-2026-45169: Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CyberArk Idira Privileged Access Manager (PAM) Self-Hosted Vaultto a version that resolves this vulnerability.Fixed in 15.0.3 - Upgrade
Upgrade
CyberArk Idira Privileged Access Manager (PAM) Self-Hosted Vaultto a version that resolves this vulnerability.Fixed in 14.6.5 - Upgrade
Upgrade
CyberArk Idira Privileged Access Manager (PAM) Self-Hosted Vaultto a version that resolves this vulnerability.Fixed in 14.2.7 - Upgrade
Upgrade
CyberArk Idira Privileged Access Manager (PAM) Self-Hosted Vaultto a version that resolves this vulnerability.Fixed in 14.0.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45169?
CVE-2026-45169 has a high severity rating of 8.7 according to the CVSS.
What type of vulnerability is CVE-2026-45169?
CVE-2026-45169 is a Denial of Service vulnerability caused by unexpected input processing.
How do I fix CVE-2026-45169?
To fix CVE-2026-45169, update Idira Privileged Access Manager (PAM) Self-Hosted Vault to versions 15.0.3, 14.6.5, 14.2.7, or 14.0.8 or later.
Which versions of Idira Privileged Access Manager are affected by CVE-2026-45169?
CVE-2026-45169 affects all Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8.
What can be the impact of CVE-2026-45169?
The impact of CVE-2026-45169 can lead to unexpected service termination under certain circumstances involving specific configurations.