imPC@ndo IT

Tracker / CVE-2026-45178

CVE-2026-45178

High 8.1

Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20

Affected products and versions

paloaltonetworks idira_secrets_manager · 13.0 → 13.8.1
paloaltonetworks idira_secrets_manager_credential_providers · 14.0 → 14.2.6

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References