Junglewise Threat Intelligence

CVE-2026-45175: Idira Endpoint Privilege Manager Agent improper access control

CVE-2026-45175 · Severity: info · CVSS 8.5 · Published 2026-06-11

Vendors: CyberArk.

Executive brief

Idira Endpoint Privilege Manager is a security tool used to manage administrative rights and protect workstations from unauthorized software. A vulnerability in the agent software allows a local user to bypass the tool's self-protection features and cryptographic checks. This could allow an attacker to disable security controls or perform unauthorized actions on the system that the software is intended to prevent.

Technical details

An improper access control vulnerability exists in the internal validation processes of the Idira Endpoint Privilege Manager Agent. The flaw, specifically related to improper certificate validation (CWE-295), allows a local attacker with low privileges to bypass cryptographic validations and the agent's built-in self-defense mechanisms. By circumventing these controls, an attacker can execute unauthorized operations that would otherwise be blocked by the EPM policy. The issue is addressed in version 26.5 of the agent across Windows, macOS, and Linux platforms.

Affected products

  • Idira (CyberArk) Endpoint Privilege Manager Agent versions prior to 26.5

Timeline

  • 2026-06-11: disclosed
  • 2026-06-11: advisory

References

Related threats