CVE-2026-45173: Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds)to a version that resolves this vulnerability.Fixed in 26.8.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45173?
CVE-2026-45173 has a high severity rating of 8.4 based on the CVSS scoring system.
How do I fix CVE-2026-45173?
To address CVE-2026-45173, update the Idira Identity Browser Extension to version 26.8.1 or later.
What causes CVE-2026-45173?
CVE-2026-45173 is caused by an origin validation failure within the internal web-page verification routines of the Idira Identity Browser Extension.
Who is affected by CVE-2026-45173?
Users of Idira Identity Browser Extension versions prior to 26.8.1 on Chrome, Firefox, and Edge are affected by CVE-2026-45173.
What types of attacks can CVE-2026-45173 enable?
CVE-2026-45173 could potentially allow for unauthorized application interaction if an authenticated user visits a specially crafted webpage.