CVE-2018-9023: Broadcom Privileged Access Manager

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

An input validation vulnerability in CA Privileged Access Manager 2.x allows unprivileged users to execute arbitrary commands by passing specially crafted arguments to the update_crld script.

Affected products

  • Broadcom Privileged Access Manager: from 2.0.0, before 3.0.0 (fixed in 3.0.0)

Published 2018-06-18. Last modified 2026-06-17.