CVE-2026-45175: Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Idira Endpoint Privilege Manager Agentto a version that resolves this vulnerability.Fixed in 26.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45175?
CVE-2026-45175 has a high severity score of 8.5.
How do I fix CVE-2026-45175?
To fix CVE-2026-45175, upgrade the Idira Endpoint Privilege Manager Agent to version 26.5 or later.
What types of attacks are possible due to CVE-2026-45175?
CVE-2026-45175 allows a local attacker to bypass security controls or cryptographic validations.
Which versions of Idira Endpoint Privilege Manager Agent are affected by CVE-2026-45175?
Idira Endpoint Privilege Manager Agent versions prior to 26.5 are affected by CVE-2026-45175.
What internal processes are affected by CVE-2026-45175?
CVE-2026-45175 affects the internal agent validation processes related to access control.