Junglewise Threat Intelligence

CVE-2026-45178: Idira Secrets Manager improper access control in cluster endpoints

CVE-2026-45178 · Severity: info · CVSS 8.4 · Published 2026-06-11

Vendors: CyberArk.

Executive brief

Idira Secrets Manager is a platform used by organizations to securely store and manage sensitive credentials like passwords and API keys. A security flaw in certain versions allows an attacker with basic access to the system's internal network to bypass security controls. This could lead to the unauthorized theft of sensitive corporate secrets or a disruption of the service, potentially impacting business operations and data privacy.

Technical details

A vulnerability classified as improper access control (CWE-284) exists in the internal cluster endpoints of Idira Secrets Manager Self-Hosted. A remote, authenticated attacker with standard node-level credentials can exploit these endpoints due to insufficient validation of access rights. Successful exploitation allows the attacker to retrieve unauthorized secrets from the manager or trigger a denial of service (DoS) condition. The vulnerability affects versions 13.8.0 and earlier; users are advised to upgrade to version 13.8.1 or later to remediate the issue.

Affected products

  • Idira (CyberArk) Secrets Manager Self-Hosted 13.8.0 and lower

Timeline

  • 2026-06-11: disclosed
  • 2026-06-11: advisory

References