CVE-2019-7442: Cyberark Enterprise Password Vault

Critical severity, CVSS 9.8. EPSS: 40% chance of exploitation in the next 30 days.

An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system.

Affected products

  • Cyberark Enterprise Password Vault: up to and including 10.7

Published 2019-05-08. Last modified 2026-06-17.