CVE-2026-45169: Palo Alto Networks Idira Privileged Access Manager Vault
High severity, CVSS 8.6. EPSS: 0.6% chance of exploitation in the next 30 days.
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17
Affected products
- Palo Alto Networks Idira Privileged Access Manager Vault: from 14.0, before 14.0.8 (fixed in 14.0.8); from 14.2, before 14.2.7 (fixed in 14.2.7); from 14.6, before 14.6.5 (fixed in 14.6.5); from 15.0, up to and including 15.0.3
Published 2026-06-12. Last modified 2026-07-07.