CVE-2026-45178: Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Restrict access to internal cluster endpoints so they are only reachable from the cluster management network or explicitly trusted hosts. Update application/network configuration or service bindings to avoid exposing internal endpoints to untrusted networks.
Idira Secrets Manager Self-Hosted internal_cluster_endpoint_access = restricted to management network / trusted hosts - Configuration
Remove or restrict node-level credentials where possible. Apply least privilege to any required node-level accounts and disable or quarantine unused node-level credentials to reduce risk of misuse.
Idira Secrets Manager Self-Hosted node_level_credentials = limit use / reduce privilege - Compensating control
Place network-level controls (firewall rules, network ACLs, or WAF) to block or restrict external access to the product's internal cluster endpoints, allowing access only from trusted management IP ranges.
- Operational
Rotate any secrets and node-level credentials that may have been exposed or are in use by the cluster prior to applying access restrictions.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45178?
CVE-2026-45178 has a high severity rating of 8.4 according to the CVSS scoring system.
How do I fix CVE-2026-45178?
To mitigate CVE-2026-45178, it is recommended to upgrade your Idira Secrets Manager Self-Hosted to version 13.8.1 or higher.
What systems are affected by CVE-2026-45178?
CVE-2026-45178 affects Idira Secrets Manager Self-Hosted versions 13.8.0 and lower.
Who can exploit CVE-2026-45178?
A remote, authenticated attacker with standard node-level credentials can exploit CVE-2026-45178 to access unauthorized secrets.
What type of vulnerability is CVE-2026-45178?
CVE-2026-45178 is classified as an improper access control vulnerability affecting internal cluster endpoints.