Executive brief
Idira Privileged Access Manager (PAM) is a security solution used by organizations to protect and manage sensitive administrative credentials. A vulnerability in the Self-Hosted Vault component could allow the service to be unexpectedly shut down when it processes malformed data. This would result in a denial-of-service, preventing authorized users from accessing the credentials needed to manage critical business systems.
Technical details
An input validation vulnerability exists in the Idira Privileged Access Manager (PAM) Self-Hosted Vault. Under specific configuration scenarios, the Vault component fails to properly validate unexpected input, which can lead to an unhandled exception or service crash. An attacker capable of sending specially crafted data to the Vault service could trigger this condition, resulting in a localized denial-of-service (DoS). The issue is resolved in versions 15.0.3, 14.6.5, 14.2.7, and 14.0.8.
Affected products
- Idira Privileged Access Manager (PAM) Self-Hosted Vault Prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8
Timeline
- 2026-06-12: disclosed
References
- https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-0-8.htm
- https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-2-7.htm
- https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-6-vault.htm
- https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew15-0-vault.htm