PT-2026-48703 · Cyberark+1 · Conjur Cloud+1

CVE-2026-45177

·

Published

2026-06-11

·

Updated

2026-06-22

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Idira Secrets Manager SaaS Edge versions prior to 1.8
Description Improper access control within internal authentication components allows a remote, unauthenticated attacker to submit a specially crafted request. This can lead to the manipulation of internal validation mechanisms, potentially bypassing identity verification and enabling the unauthorized acquisition of an access token.
Recommendations Update Idira Secrets Manager SaaS Edge to version 1.8 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45177

Affected Products

Conjur Cloud
Idira Secrets Manager Edge