Description
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17
Published: 2026-06-12
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in input validation logic of Idira Privileged Access Manager Self‑Hosted Vault versions before 15.0.3, 14.6.5, 14.2.7, and 14.0.8. When the system processes carefully crafted unexpected input, it can terminate the service unexpectedly, leading to a localized denial of service. The weakness is classified as CWE‑400, indicating a failure to properly validate input length or format. This flaw does not grant code execution or unauthorized access, but it can disrupt the availability of the service for authenticated users on the affected instance.

Affected Systems

The affected software is CyberArk’s Idira Privileged Access Manager self‑hosted Vault product. Identified in the CNA data as a CyberArk Software, a Palo Alto Networks Company product. Versions prior to 15.0.3 (including 14.6.5, 14.2.7, and 14.0.8) are affected; post‑15.0.3 releases include the fix.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity, and although the EPSS score is not available, the vulnerability could be leveraged by an attacker who can inject unexpected input via the service’s exposed interfaces—likely through rest endpoints or management console. Because the denial of service is localized, the attacker must reach the affected system, but any successful exploitation would cause a service outage for all privileged users until the system is restarted. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits at the time of this analysis.

Generated by OpenCVE AI on June 12, 2026 at 06:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Idira PAM Self‑Hosted Vault to the fixed release (15.0.3 or later, or at least 14.6.5, 14.2.7, or 14.0.8 as indicated in the vendor release notes).
  • If upgrading immediately is not feasible, restrict the exposed interfaces that accept user input, such as disabling unnecessary REST APIs or implementing network segmentation to limit traffic to trusted hosts.
  • Apply temporary input‑validation filters or rate limits on incoming requests to reject oversized or malformed payloads, mitigating the risk of accidental service termination until a permanent patch is deployed.

Generated by OpenCVE AI on June 12, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 12 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Description Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17
Title Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing
First Time appeared Cyberark Software A Palo Alto Networks Company
Cyberark Software A Palo Alto Networks Company pam Sh Vault
Weaknesses CWE-400
CPEs cpe:2.3:a:cyberark_software_a_palo_alto_networks_company:pam_sh_vault:*:*:*:*:*:*:*:*
Vendors & Products Cyberark Software A Palo Alto Networks Company
Cyberark Software A Palo Alto Networks Company pam Sh Vault
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/U:Amber'}


Subscriptions

Cyberark Software A Palo Alto Networks Company Pam Sh Vault
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-06-12T04:32:03.440Z

Reserved: 2026-05-08T23:00:57.503Z

Link: CVE-2026-45169

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-12T05:16:32.703

Modified: 2026-06-12T05:16:32.703

Link: CVE-2026-45169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T06:30:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption