CVE-2026-45171: Idira PSM Arbitrary Code Execution – Patch Guidance & Risk Assessment
CVE-2026-45171 is a high-severity vulnerability in Idira Privileged Session Manager that allows authenticated users with basic (low-privileged) access to execute arbitrary code on affected systems. The flaw stems from incomplete validation of user input combined with overly permissive folder access controls. An attacker who already has login credentials—even with minimal permissions—could exploit this to gain full system control, making it a critical concern for organizations relying on PSM for credential and session management.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-22
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-11 / 2026-06-23
NVD description (verbatim)
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18
4 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability arises from two compounding weaknesses: insufficient input validation on user-supplied data and improper configuration of directory permissions within the PSM application. The combination allows an authenticated, low-privileged user to bypass intended security boundaries and achieve arbitrary code execution. CyberArk has published security bulletins CA26-17 and CA26-18 documenting the issue. The CVSS 3.1 score of 8.8 (HIGH) reflects the network-accessible attack surface, low attack complexity, and the severe impact across confidentiality, integrity, and availability when successfully exploited.
Business impact
Idira PSM is typically deployed to centralize and audit privileged session management across enterprise infrastructure. Compromise of PSM itself represents a critical control failure: an attacker with arbitrary code execution could intercept credentials, tamper with session logs, pivot to downstream systems, or establish persistence. This undermines the entire trust model that PSM is meant to enforce, potentially exposing high-value systems and sensitive data that the session manager was designed to protect.
Affected systems
Idira Privileged Session Manager versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5 are affected. Organizations running any of these four release branches must upgrade to their respective patched version. Verify your current PSM version and patch level against the CyberArk advisory to determine exposure.
Exploitability
The attack requires prior authentication and low-privilege user credentials, which moderately constrains the threat model compared to unauthenticated attacks. However, the presence of low-privileged accounts (developers, junior admins, contractors) in many enterprises means the barrier to initial compromise is realistic. Once inside, the attacker faces low technical complexity in weaponizing the input validation flaw and folder permission misconfiguration. The network-accessible nature of PSM—often exposed to multiple internal teams—compounds risk.
Remediation
Upgrade Idira PSM to one of the patched versions: 15.0.3 or later (for 15.x branch), 14.6.3 or later (for 14.6 branch), 14.2.5 or later (for 14.2 branch), or 14.0.5 or later (for 14.0 branch). Consult CyberArk Security Bulletins CA26-17 and CA26-18 for version-specific upgrade procedures, prerequisites, and any required system changes.
Patch guidance
Review CyberArk's published patch guidance in bulletins CA26-17 and CA26-18. Plan upgrades during maintenance windows; coordinate with teams that depend on PSM access. After patching, validate that folder permissions have been correctly applied and that input validation controls are functioning as intended. Consider running a post-patch vulnerability scan to confirm remediation.
Detection guidance
Monitor PSM access logs for unusual activity by low-privileged users, particularly attempts to access or write to sensitive application folders, pass suspicious input to configuration or session management endpoints, or execute child processes. Watch for authentication events followed by elevation attempts or lateral movement. Network detection should flag anomalous outbound connections from PSM hosts. Intrusion detection systems should be tuned to alert on exploitation patterns targeting file path traversal (CWE-22) vectors within PSM application traffic.
Why prioritize this
This vulnerability merits urgent remediation due to its HIGH CVSS score, the privileged role of PSM in enterprise infrastructure, and the realistic attack scenario (low-privileged insiders or attackers who have compromised a basic account). PSM is a crown-jewel control; its compromise cascades risk across downstream systems. The combination of incomplete input validation and permission misconfiguration is also a common architectural pattern that may persist in related systems, warranting a broader security review.
Risk score, explained
The CVSS 3.1 score of 8.8 reflects: (1) Network-accessible attack surface (AV:N); (2) low attack complexity requiring only standard exploitation techniques (AC:L); (3) requirement for low-privilege authentication (PR:L), not unauthenticated access; (4) no user interaction required (UI:N); (5) impact limited to a single PSM instance, not the broader system landscape (S:U); and (6) complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). The absence of elevated privileges required and the ease of exploitation elevate risk despite the authentication prerequisite.
Frequently asked questions
Does CVE-2026-45171 affect all Idira PSM versions?
No. The vulnerability affects versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5. If you are running any of these versions, check your exact patch level and upgrade to the corresponding patched release. Verify against CyberArk's advisory to confirm your version is safe.
Can this vulnerability be exploited by an attacker without legitimate credentials?
No, the attack requires an authenticated user account with at least low-privilege permissions. However, many organizations have numerous low-privileged accounts (developers, support staff, contractors) that could be compromised or misused. The authentication requirement does not eliminate risk; it shifts the attack model to insider threats or post-compromise lateral movement.
What happens if an attacker exploits this vulnerability?
An attacker would gain arbitrary code execution on the PSM system, potentially allowing them to steal credentials stored or managed by PSM, tamper with audit logs, compromise downstream systems connected through PSM, or establish persistent backdoor access. The impact is severe because PSM is a trust anchor for privilege management across the enterprise.
Do I need to change my approach if I have already patched?
After patching, validate that the update was successful and that folder permissions have been correctly applied. Review PSM access logs for any suspicious activity that may have occurred before the patch was applied. Consider reviewing low-privileged account access policies and monitoring to reduce future risk from similar vectors.
This analysis is provided for informational purposes and does not constitute a complete security assessment. Organizations must verify all version numbers, patch availability, and compatibility against official CyberArk security bulletins CA26-17 and CA26-18 before making remediation decisions. Threat modeling and prioritization should account for your specific environment, network architecture, and business criticality. Consult with your vendor, internal security team, and system administrators before deploying patches. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-0270HIGHCortex XSOAR Path Traversal on Linux — Exploit Requirements & Patching Guide
- CVE-2016-20076HIGHWordPress Simple-Backup 2.7.11 Unauthenticated File Access & Deletion Vulnerability
- CVE-2016-20081HIGHHB Audio Gallery Lite Path Traversal Vulnerability – Unauthenticated File Download
- CVE-2017-20248HIGHApptha Slider Gallery Path Traversal Vulnerability
- CVE-2017-20250HIGHMac Photo Gallery 3.0 Path Traversal File Download Vulnerability
- CVE-2018-25408HIGHOpen ISES Project Path Traversal Vulnerability (High Severity)
- CVE-2024-40646HIGHVertex Path Traversal Vulnerability – Remote File Access Risk
- CVE-2026-10108HIGHUnauthenticated Path Traversal in xiaomusic v0.5.7 – File Read Vulnerability