Junglewise Threat Intelligence

CVE-2026-45172: Idira Privileged Session Manager for SSH command injection

CVE-2026-45172 · Severity: info · CVSS 8.7 · Published 2026-06-11

Vendors: CyberArk.

Executive brief

A vulnerability in the Idira Privileged Session Manager for SSH (PSMP) allows a user with low-level access to take control of the underlying server. This component is typically used to secure and monitor administrative access to sensitive systems; an exploit could allow an attacker to bypass security controls and execute unauthorized commands. Organizations should update to the latest patched versions to prevent potential system compromise.

Technical details

An OS command injection vulnerability (CWE-78) exists in Idira Privileged Session Manager for SSH (PSMP) due to incomplete input validation. An authenticated attacker with low privileges can exploit this flaw via the network to execute arbitrary commands on the PSMP host. The vulnerability affects versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6. Patches have been released by the vendor to address this issue by improving input sanitization.

Affected products

  • Idira Privileged Session Manager for SSH (PSMP) Prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6

Timeline

  • 2026-06-11: disclosed: CVE published to NVD dataset

References