CVE-2026-45178: CWE-284: Improper Access Control in CyberArk Software, a Palo Alto Networks Company Conjur Enterprise
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20
AI Analysis
Technical Summary
This vulnerability (CVE-2026-45178) affects Conjur Enterprise's Idira Secrets Manager Self-Hosted versions 13.8.0 and lower, where improper access control in internal cluster endpoints could be exploited by a remote attacker who has standard node-level authentication. The attacker could leverage these endpoints to access secrets they are not authorized to retrieve or cause a denial of service. The CVSS 4.0 base score is 8.4, indicating high severity, with network attack vector, low attack complexity, and no user interaction required. The vulnerability is categorized under CWE-284 (Improper Access Control). There is no vendor advisory indicating an available patch or fix at this time.
Potential Impact
An attacker with standard node-level credentials can remotely exploit this vulnerability to retrieve unauthorized secrets or disrupt service availability via denial of service. This compromises confidentiality and availability of sensitive information managed by Conjur Enterprise. The high CVSS score reflects the significant risk posed by this improper access control issue.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to internal cluster endpoints to trusted personnel only and monitor for unusual activity involving node-level credentials. Follow CyberArk's security bulletins for updates on remediation.
CVE-2026-45178: CWE-284: Improper Access Control in CyberArk Software, a Palo Alto Networks Company Conjur Enterprise
Description
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20
CVSS v4.0
Score 8.4high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-45178) affects Conjur Enterprise's Idira Secrets Manager Self-Hosted versions 13.8.0 and lower, where improper access control in internal cluster endpoints could be exploited by a remote attacker who has standard node-level authentication. The attacker could leverage these endpoints to access secrets they are not authorized to retrieve or cause a denial of service. The CVSS 4.0 base score is 8.4, indicating high severity, with network attack vector, low attack complexity, and no user interaction required. The vulnerability is categorized under CWE-284 (Improper Access Control). There is no vendor advisory indicating an available patch or fix at this time.
Potential Impact
An attacker with standard node-level credentials can remotely exploit this vulnerability to retrieve unauthorized secrets or disrupt service availability via denial of service. This compromises confidentiality and availability of sensitive information managed by Conjur Enterprise. The high CVSS score reflects the significant risk posed by this improper access control issue.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to internal cluster endpoints to trusted personnel only and monitor for unusual activity involving node-level credentials. Follow CyberArk's security bulletins for updates on remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- palo_alto
- Date Reserved
- 2026-05-08T23:01:00.502Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a2b05c8815e7002b81e9b63
Added to database: 6/11/2026, 7:00:24 PM
Last enriched: 6/11/2026, 7:16:27 PM
Last updated: 6/12/2026, 3:58:21 AM
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.