Junglewise Threat Intelligence

CVE-2026-45176: Idira Endpoint Privilege Manager Agent privilege escalation

CVE-2026-45176 · Severity: info · CVSS 8.9 · Published 2026-06-11

Vendors: CyberArk.

Executive brief

Idira Endpoint Privilege Manager is a security tool used to manage and restrict administrative rights on corporate computers. A vulnerability in the agent software could allow a user with limited access to bypass security controls and perform unauthorized actions with high-level system privileges. This could lead to a full compromise of the affected workstation or server, potentially allowing for the installation of malicious software or access to sensitive data.

Technical details

The vulnerability is classified as improper privilege management (CWE-269) within high-privileged components of the Idira Endpoint Privilege Manager Agent. A local, low-privileged attacker can exploit this by manipulating internal communication mechanisms or file operations. Under specific conditions, this manipulation allows the attacker to bypass permission restrictions and execute unauthorized actions with elevated privileges. The attack requires local access and is characterized by high complexity (AC:H) according to the CVSS 4.0 vector. The issue is addressed in version 26.5 of the agent across Linux, macOS, and Windows platforms.

Affected products

  • Idira (CyberArk) Endpoint Privilege Manager Agent versions prior to 26.5

Timeline

  • 2026-06-11: disclosed
  • 2026-06-11: advisory

References

Related threats