CVE-2026-45175: Palo Alto Networks Idira Endpoint Privilege Manager
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent self-defense mechanisms and execute unauthorized operations. CyberArk Security Bulletin: CA26-19
Affected products
- Palo Alto Networks Idira Endpoint Privilege Manager: before 26.5.0 (fixed in 26.5.0)
Published 2026-06-11. Last modified 2026-06-22.