cyberark
Latest CVEs
The 15 most recently published vulnerabilities affecting cyberark.
- CVE-2026-2914CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs7.8
- CVE-2025-66374CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task.7.8
- CVE-2025-13762Client-Side Denial of Service Condition in SWS Extension prior to version 2.2.30305
- CVE-2025-46382CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5.3
- CVE-2025-49831Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to IAM Authenticator Bypass via Mis-configured Network Device9.8
- CVE-2025-49830Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to path traversal and file disclosure6.5
- CVE-2025-49829Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) missing validations6.5
- CVE-2025-49828Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Remote Code Execution8.8
- CVE-2025-49827Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) Vulnerable to Bypass of IAM Authenticator9.8
- CVE-2025-22274HTML injection in CyberArk Endpoint Privilege Manager
- CVE-2025-22273Lack of rate-limiting in password change mechanism in CyberArk Endpoint Privilege Manager
- CVE-2025-22272Self Reflected XSS in CyberArk Endpoint Privilege Manager
- CVE-2025-22271IP Spoofing in CyberArk Endpoint Privilege Manager
- CVE-2025-22270Stored XSS in CyberArk Endpoint Privilege Manager
- CVE-2024-57967PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.4.2