Junglewise Threat Intelligence

CVE-2026-45171: Idira Privileged Session Manager arbitrary code execution via path traversal

CVE-2026-45171 · Severity: info · CVSS 9.3 · Published 2026-06-11

Executive brief

A security vulnerability in Idira Privileged Session Manager (PSM) could allow a user with low-level access to take full control of the system. PSM is a tool used by organizations to monitor and secure administrative access to sensitive servers. If exploited, an attacker could execute unauthorized commands, potentially compromising the entire security platform and the sensitive data it protects.

Technical details

This vulnerability stems from a combination of incomplete input validation (CWE-22, Path Traversal) and weak folder permissions within the Idira Privileged Session Manager (PSM) component. An attacker must be authenticated with low-level privileges on the local system to exploit these flaws. By leveraging the improper path validation and insecure directory permissions, the attacker can achieve arbitrary code execution with elevated privileges. The issue is addressed in versions 15.0.3, 14.6.3, 14.2.5, and 14.0.5.

Affected products

  • Idira Privileged Session Manager (PSM) Prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5

Timeline

  • 2026-06-11: disclosed: CVE published to NVD dataset

References