CVE-2026-45173: Palo Alto Networks Idira Identity Browser Extension
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21
Affected products
- Palo Alto Networks Idira Identity Browser Extension: from 26.0.0, before 26.8.1 (fixed in 26.8.1)
Published 2026-06-11. Last modified 2026-06-22.