CVE-2026-45178: Palo Alto Networks Idira Secrets Manager

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20

Affected products

  • Palo Alto Networks Idira Secrets Manager: from 13.0, before 13.8.1 (fixed in 13.8.1)
  • Palo Alto Networks Idira Secrets Manager Credential Providers: from 14.0, before 14.2.6 (fixed in 14.2.6)

Published 2026-06-11. Last modified 2026-06-22.