CVE-2026-45177: Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal validation mechanisms, potentially leading to a bypass of identity verification and the unauthorized acquisition of an access token. CyberArk Security Bulletin: CA26-20
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Idira Secrets Manager SaaS Edgeto a version that resolves this vulnerability.Fixed in 1.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45177?
The severity of CVE-2026-45177 is critical with a CVSS score of 9.1.
What does CVE-2026-45177 involve?
CVE-2026-45177 involves an authentication bypass vulnerability in Idira Secrets Manager SaaS Edge allowing remote, unauthenticated access.
How can I fix CVE-2026-45177?
To fix CVE-2026-45177, upgrade Idira Secrets Manager SaaS Edge to version 1.8 or later.
What are the potential impacts of CVE-2026-45177?
The potential impacts of CVE-2026-45177 include unauthorized manipulation of sensitive information by an attacker.
Who is affected by CVE-2026-45177?
All users of Idira Secrets Manager SaaS Edge versions prior to 1.8 are affected by CVE-2026-45177.