https://seclists.org/oss-sec/2025/q3/80: Five new CVEs published for Cyberark Conjur OSS
Published Aug 8, 2025
·Updated
Affected Software
1 affected component
CyberArk Conjur OSS
Frequently Asked Questions
1
What is the severity of CVE-2025-49827?
CVE-2025-49827 is classified as critical due to a bypass of IAM Authenticator in Secrets Manager.
2
How do I fix CVE-2025-49827?
To fix CVE-2025-49827, update the CyberArk Conjur OSS software to the latest version provided by CyberArk.
3
What are the potential impacts of CVE-2025-49827?
The potential impacts of CVE-2025-49827 include unauthorized access to secrets managed by the Conjur OSS product.
4
Who is affected by CVE-2025-49827?
Any users or organizations utilizing the CyberArk Conjur OSS product with IAM Authenticator are affected by CVE-2025-49827.
5
When was CVE-2025-49827 published?
CVE-2025-49827 was published on August 8, 2025.