CVE-2026-2914: Cyberark Endpoint Privilege Manager

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs

Affected products

  • Cyberark Endpoint Privilege Manager: before 25.11.0 (fixed in 25.11.0)

Published 2026-02-25. Last modified 2026-06-17.