CVE-2026-45170: Palo Alto Networks Idira Privilege Cloud Connector

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17

Affected products

  • Palo Alto Networks Idira Privilege Cloud Connector: from 1.1.0, before 1.1.100504 (fixed in 1.1.100504)

Published 2026-06-12. Last modified 2026-06-23.