Home
HIGH: 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:AmberDefault status
unaffected
1.1.0 (custom) before 1.1.100504
affected
Description
Idira Privilege Cloud Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17
Problem types
CWE-295 - Improper Certificate Validation
Product status
1.1.0 (custom) before 1.1.100504
Timeline
| 2026-06-11: | Initial publication. |
Credits
Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue
References
docs.cyberark.com/