CVE-2026-45170: Idira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to Incomplete TLS Certificate Validation
Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Idira Vendor PAM - Self-Hosted Connectorto a version that resolves this vulnerability.Fixed in 1.1.100504Patch CA26-17
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45170?
CVE-2026-45170 has a high severity rating of 7.5 according to the CVSS v4.0.
How do I fix CVE-2026-45170?
To mitigate CVE-2026-45170, upgrade to Idira Privilege Cloud Connector version 1.1.100504 or later, ensuring complete TLS certificate validation.
What systems are affected by CVE-2026-45170?
CVE-2026-45170 affects specific versions of Idira Privilege Cloud Connector prior to version 1.1.100504.
What risks are associated with CVE-2026-45170?
The risk associated with CVE-2026-45170 includes potential security bypass due to incomplete TLS certificate validation.
When was CVE-2026-45170 announced?
CVE-2026-45170 was published on June 12, 2026, by CyberArk Security Bulletin.