Junglewise Threat Intelligence

CVE-2025-13762: CyberArk Secure Web Sessions Extension improper input validation in SWS session initialization

CVE-2025-13762 · Severity: info · Published 2025-11-27

Vendors: CyberArk.

Executive brief

CyberArk Secure Web Sessions Extension is a browser plugin for Chrome and Edge that enables secure credential-based web access. An improper input validation flaw allows an attacker to cause a denial of service by triggering a crash or hang when initiating new SWS sessions, disrupting authorized users' ability to access corporate web applications.

Technical details

This vulnerability is a class of improper input validation in the CyberArk Secure Web Sessions Extension before version 2.2.30305. The flaw exists in the session initialization logic, where insufficient validation of user input or session parameters allows an attacker to craft malformed requests that trigger a denial of service condition. The attack vector is network-based, as it can be triggered remotely when a user attempts to start a new SWS session. No authentication bypass or data exposure is reported; the impact is limited to service disruption.

Affected products

  • CyberArk Secure Web Sessions Extension before 2.2.30305

Timeline

  • 2025-11-27: disclosed: Vulnerability published on NVD

References