https://seclists.org/oss-sec/2025/q3/49: Five new CVEs published for Cyberark Conjur OSS
Published Jul 16, 2025
·Updated
Affected Software
1 affected component
CyberArk Conjur OSS
Frequently Asked Questions
1
What is the severity of CVE-2025-49827?
CVE-2025-49827 has a critical severity rating due to a bypass of IAM Authenticator in Secrets Manager.
2
How do I fix CVE-2025-49827?
To fix CVE-2025-49827, update to the latest version of CyberArk Conjur OSS where the vulnerability has been patched.
3
What are the risks associated with CVE-2025-49827?
The risks associated with CVE-2025-49827 include unauthorized access to sensitive data by bypassing authentication mechanisms.
4
Is CVE-2025-49827 applicable to both Self-Hosted and OSS versions?
Yes, CVE-2025-49827 affects both Self-Hosted (formerly Conjur Enterprise) and Conjur OSS versions of the product.
5
When was CVE-2025-49827 disclosed?
CVE-2025-49827 was disclosed on July 15, 2025.