← Back

Cyberark

cyberark

30 CVEs • 11 products

Products (11)

Click to collapse
Toggle

CVEs (30)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cyberark
1Endpoint Privilege Manager
Feb 27, 2026
Feb 25, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs
1Cyberark
1Endpoint Privilege Manager
Feb 28, 2026
Feb 3, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task.
1Cyberark
1Conjur
Nov 4, 2025
Jul 15, 2025
9.1 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker...Show more
An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious server under the attacker’s control. CyberArk believes there to be very few installations where this issue can be actively exploited, though Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1 may be affected. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.Show less
1Cyberark
1Conjur
Nov 4, 2025
Jul 15, 2025
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to load policy can use the policy yaml parser to reference files on the Secrets Manager, Self-Hosted s...Show more
Conjur provides secrets management and application identity for infrastructure. An authenticated attacker who is able to load policy can use the policy yaml parser to reference files on the Secrets Manager, Self-Hosted server. These references may be used as reconnaissance to better understand the folder structure of the Secrets Manager/Conjur server or to have the yaml parser include files on the server in the yaml that is processed as the policy loads. This issue affects Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.Show less
1Cyberark
1Conjur
Nov 4, 2025
Jul 15, 2025
6.0 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authenticated attackers to inject resources into the database and to bypass permi...Show more
Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authenticated attackers to inject resources into the database and to bypass permission checks. This issue affects Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.Show less
1Cyberark
1Conjur
Nov 4, 2025
Jul 15, 2025
8.6 HIGH· v4
8.8 HIGH· v3
N/A· v2
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vul...Show more
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An authenticated attacker who can inject secrets or templates into the Secrets Manager, Self-Hosted database could take advantage of an exposed API endpoint to execute arbitrary Ruby code within the Secrets Manager process. This issue affects both Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS. Conjur OSS version 1.21.2 and Secrets Manager, Self-Hosted version 13.5 fix the issue.Show less
1Cyberark
1Conjur
Nov 4, 2025
Jul 15, 2025
9.1 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.0 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.5 and 13.6...Show more
Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.22.0 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.5 and 13.6 are vulnerable to bypass of the IAM authenticator. An attacker who can manipulate the headers signed by AWS can take advantage of a malformed regular expression to redirect the authentication validation request that Secrets Manager, Self-Hosted sends to AWS to a malicious server controlled by the attacker. This redirection could result in a bypass of the Secrets Manager, Self-Hosted IAM Authenticator, granting the attacker the permissions granted to the client whose request was manipulated. This issue affects both Secrets Manager, Self-Hosted (formerly Conjur Enterprise) and Conjur OSS. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.Show less
1Cyberark
1Privileged Access Manager
Mar 14, 2025
Feb 3, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
1Cyberark
1Identity
Aug 30, 2024
Aug 25, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security
1Cyberark
1Identity
Aug 30, 2024
Aug 25, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
1Cyberark
1Identity
Aug 30, 2024
Aug 25, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
1Cyberark
1Identity
Aug 30, 2024
Aug 25, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
1Cyberark
1Viewfinity
Jan 30, 2025
May 3, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user via a bug within the "add printer" option.
1Cyberark
1Identity
Nov 21, 2024
Mar 3, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value...Show more
CyberArk Identity versions up to and including 22.1 in the 'StartAuthentication' resource, exposes the response header 'X-CFY-TX-TM'. In certain configurations, that response header contains different, predictable value ranges which can be used to determine whether a user exists in the tenant.Show less
1Cyberark
1Endpoint Privilege Manager
Nov 21, 2024
Jan 15, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.
1Cyberark
1Credential Provider
Nov 21, 2024
Sep 2, 2021
N/A· v4
4.4 MEDIUM· v3
1.9 LOW· v2
The effective key space used to encrypt the cache in CyberArk Credential Provider prior to 12.1 has low entropy, and under certain conditions a local malicious user can obtain the plaintext of cache files.
1Cyberark
1Credential Provider
Nov 21, 2024
Sep 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (fo...Show more
An inadequate encryption vulnerability discovered in CyberArk Credential Provider before 12.1 may lead to Information Disclosure. An attacker may realistically have enough information that the number of possible keys (for a credential file) is only one, and the number is usually not higher than 2^36.Show less
1Cyberark
1Credential Provider
Nov 21, 2024
Sep 2, 2021
N/A· v4
5.1 MEDIUM· v3
1.9 LOW· v2
The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure.
1Cyberark
1Identity
Nov 21, 2024
Sep 1, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used...Show more
CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is valid. In certain authentication policy configurations with MFA, the API response length can be used to differentiate between a valid user and an invalid one (aka Username Enumeration). Response differentiation enables attackers to enumerate usernames of valid application users. Attackers can use this information to leverage brute-force and dictionary attacks in order to discover valid account information such as passwords.Show less
1Cyberark
1Endpoint Privilege Manager
Nov 21, 2024
Nov 27, 2020
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that...Show more
CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a process that normally has credential access, such as a Chrome process that reads credentials from a SQLite database.Show less