Executive brief
The Idira Privilege Cloud Connector, a tool used to securely connect local infrastructure to cloud-based identity management services, contains a security flaw where it may fail to properly verify digital certificates. This could allow an attacker on the same local network to intercept or modify sensitive data as it travels between the connector and the cloud service. If exploited, this could lead to the exposure of administrative credentials or a disruption of identity management operations.
Technical details
A vulnerability classified as Improper Certificate Validation (CWE-295) exists in the Idira Privilege Cloud Connector. Under specific conditions and configuration scenarios, the application fails to fully enforce TLS certificate validation during encrypted communications. An attacker positioned on an adjacent network (such as a local area network) could exploit this weakness to perform a man-in-the-middle (MitM) attack. Successful exploitation requires some user interaction and specific deployment conditions, but could result in a total loss of confidentiality, integrity, and availability for the affected connection. The issue is addressed in version 1.1.100504.
Affected products
- Idira (CyberArk) Privilege Cloud Connector versions prior to 1.1.100504
Timeline
- 2026-06-12: disclosed: Initial NVD publication date