Junglewise Threat Intelligence

CVE-2026-45174: Idira Endpoint Privilege Manager Linux Agent compromise in daemon initialization

CVE-2026-45174 · Severity: info · CVSS 8.5 · Published 2026-06-11

Vendors: CyberArk.

Executive brief

A security vulnerability exists in the Idira Endpoint Privilege Manager Linux Agent, a tool used to manage administrative permissions and security policies on Linux systems. A local user on the system could exploit a flaw during the agent's startup process to compromise the background service that enforces security rules. This could allow an attacker to bypass security controls or gain unauthorized elevated privileges on the affected machine.

Technical details

A vulnerability in the Idira (CyberArk) Endpoint Privilege Manager Linux Agent allows for a compromise of the agent daemon during its initialization phase. The flaw is categorized under CWE-404 (Improper Resource Shutdown or Release), suggesting that mishandled resources during the startup of the privileged daemon can be manipulated by a local attacker. An attacker with low-level local access can exploit this to interfere with the daemon's integrity, potentially leading to full system compromise or elevation of privilege. The issue is resolved in version 26.5 of the Linux Agent.

Affected products

  • Idira (CyberArk) Endpoint Privilege Manager Linux Agent versions prior to 26.5

Timeline

  • 2026-06-11: disclosed
  • 2026-06-11: advisory

References