PT-2026-48703 · Cyberark+1 · Conjur Cloud+1
CVE-2026-45177
·
Published
2026-06-11
·
Updated
2026-06-22
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Idira Secrets Manager SaaS Edge versions prior to 1.8
Description
Improper access control within internal authentication components allows a remote, unauthenticated attacker to submit a specially crafted request. This can lead to the manipulation of internal validation mechanisms, potentially bypassing identity verification and enabling the unauthorized acquisition of an access token.
Recommendations
Update Idira Secrets Manager SaaS Edge to version 1.8 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Conjur Cloud
Idira Secrets Manager Edge