Executive brief
The Idira Identity Browser Extension, used for managing corporate identities and credentials, contains a security flaw in how it verifies the source of web pages. If a user visits a malicious website while logged into the extension, an attacker could trick the extension into performing unauthorized actions or changing settings. This could lead to the exposure of sensitive session information or unauthorized access to corporate resources managed by the tool.
Technical details
An origin validation error (CWE-346) exists in the internal web-page verification routines of the Idira Identity Browser Extension. The vulnerability is triggered when an authenticated user navigates to a specially crafted webpage, allowing a remote attacker to bypass origin checks. This can be used to execute unauthorized application commands or modify execution parameters within the context of the user's browser session. The flaw affects Chrome, Firefox, and Edge builds prior to version 26.8.1. Users are advised to update to version 26.8.1 or later to remediate the issue.
Affected products
- CyberArk Idira Identity Browser Extension < 26.8.1
Timeline
- 2026-06-11: disclosed
- 2026-06-11: advisory