High severityNVD Advisory· Published Jun 11, 2026· Updated Jun 12, 2026
CVE-2026-45171
CVE-2026-45171
Description
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: < 15.0.3, < 14.6.3, < 14.2.5, < 14.0.5
Patches
Vulnerability mechanics
References
4- docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-0-5.htmnvd
- docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-2-5.htmnvd
- docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-6-psm.htmnvd
- docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew15-0-psm.htmnvd
News mentions
0No linked articles in our index yet.