Back

HIGH

Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints

Published Jun 11, 2026

Description

Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS). CyberArk Security Bulletin: CA26-20

Affected products

Remediation

Vendor solution

VERSION MINOR VERSION SUGGESTED SOLUTION Conjur Enterprise on Idira Secrets Manager 13.0 through 13.8.0 Upgrade to 13.8.1 or later. Conjur Enterprise on Central Credential Provider (CCP) 14.0 through 14.2.5 Upgrade to 14.2.6 or later. Conjur Enterprise on z/OS Credential Provider 14.0 through 14.2.5 Upgrade to 14.2.6 or later. Conjur Enterprise on Credential Provider (CP) 14.0 through 14.2.5 Upgrade to 14.2.6 or later.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner palo_alto
Published Jun 11, 2026
Updated Jun 11, 2026
Reserved May 8, 2026

CISA Vulnrichment

Updated Jun 11, 2026

NVD

Status Analyzed
Modified Jun 22, 2026

Red Hat

No data

ENISA EUVD

Assigner palo_alto
Published Jun 11, 2026
Updated Jun 11, 2026

GitHub

No data