Executive brief
CyberArk Secure Web Sessions Extension is a browser plugin for Chrome and Edge that enables secure credential-based web access. An improper input validation flaw allows an attacker to cause a denial of service by triggering a crash or hang when initiating new SWS sessions, disrupting authorized users' ability to access corporate web applications.
Technical details
This vulnerability is a class of improper input validation in the CyberArk Secure Web Sessions Extension before version 2.2.30305. The flaw exists in the session initialization logic, where insufficient validation of user input or session parameters allows an attacker to craft malformed requests that trigger a denial of service condition. The attack vector is network-based, as it can be triggered remotely when a user attempts to start a new SWS session. No authentication bypass or data exposure is reported; the impact is limited to service disruption.
Affected products
- CyberArk Secure Web Sessions Extension before 2.2.30305
Timeline
- 2025-11-27: disclosed: Vulnerability published on NVD