Junglewise Threat Intelligence

CVE-2026-45177: Idira Secrets Manager SaaS Edge auth bypass in internal components

CVE-2026-45177 · Severity: info · CVSS 9.1 · Published 2026-06-11

Executive brief

Idira Secrets Manager SaaS Edge, a tool used to manage and protect sensitive credentials, contains a security flaw in how it verifies user identities. An unauthenticated attacker could send a malicious request to bypass security checks and obtain an access token. This could allow an unauthorized person to gain access to sensitive corporate secrets and credentials.

Technical details

An improper access control vulnerability (CWE-284) exists in the internal authentication components of Idira Secrets Manager SaaS Edge. A remote, unauthenticated attacker can exploit this by submitting a specially crafted request to manipulate internal validation mechanisms. Successful exploitation allows the attacker to bypass identity verification and acquire an unauthorized access token. The vulnerability is present in versions prior to 1.8 and has been addressed in version 1.8. The attack requires no user interaction and can be performed over the network, though it may require specific environmental conditions (Attack Requirements: Present).

Affected products

  • Idira Secrets Manager SaaS Edge versions prior to 1.8

Timeline

  • 2026-06-11: disclosed
  • 2026-06-11: advisory: NVD publication date

References