Home

Description

Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17

PUBLISHED Reserved 2026-05-08 | Published 2026-06-12 | Updated 2026-06-12 | Assigner palo_alto




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/U:Amber

Problem types

CWE-400: Uncontrolled Resource Consumption

Product status

Default status
unaffected

14.0 (custom) before 14.0.8
affected

14.2 (custom) before 14.2.7
affected

14.6 (custom) before 14.6.5
affected

15.0 (custom) before 15.0.3
affected

Timeline

2026-06-11:Initial publication.

Credits

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue finder

References

docs.cyberark.com/...release notes/rn-whatsnew15-0-vault.htm vendor-advisory

docs.cyberark.com/...release notes/rn-whatsnew14-6-vault.htm vendor-advisory

docs.cyberark.com/...ent/release notes/rn-whatsnew14-2-7.htm vendor-advisory

docs.cyberark.com/...ent/release notes/rn-whatsnew14-0-8.htm vendor-advisory

cve.org (CVE-2026-45169)

nvd.nist.gov (CVE-2026-45169)

Download JSON