CVE-2026-45176: Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation Manipulation
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow the attacker to bypass permission restrictions and execute unauthorized local actions with elevated privileges. CyberArk Security Bulletin: CA26-19
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Idira Endpoint Privilege Manager Agentto a version that resolves this vulnerability.Fixed in 26.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45176?
CVE-2026-45176 has a severity rating of high with a CVSS score of 8.9.
How do I fix CVE-2026-45176?
To mitigate CVE-2026-45176, update the Idira Endpoint Privilege Manager Agent to version 26.5 or later.
What types of attacks are possible with CVE-2026-45176?
CVE-2026-45176 allows local, low-privileged attackers to escalate privileges via internal communication manipulation or file operations.
What software is affected by CVE-2026-45176?
CVE-2026-45176 affects all versions of the Idira Endpoint Privilege Manager Agent prior to 26.5.
What are the potential impacts of CVE-2026-45176?
Exploitation of CVE-2026-45176 could lead to unauthorized local privilege escalation and control over sensitive system components.