CVE-2026-45169

EUVD-2026-36385
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 28.2%
Affected Products (NVD)
VendorProductVersion
paloaltonetworksidira_privileged_access_manager_vault
14.0 ≤
𝑥
< 14.0.8
paloaltonetworksidira_privileged_access_manager_vault
14.2 ≤
𝑥
< 14.2.7
paloaltonetworksidira_privileged_access_manager_vault
14.6 ≤
𝑥
< 14.6.5
paloaltonetworksidira_privileged_access_manager_vault
15.0 ≤
𝑥
≤ 15.0.3
𝑥
= Vulnerable software versions