216.73.217.22

CVE-2026-45173

· Published 12/06/2026 00:16 · Modified 12/06/2026 15:30 · Author: The MITRE Corporation

Labels: CVE-2026-45173 2026-06-11CVE-2026-45173CWE-346[email protected]

Essential information

Published
12/06/2026 00:16
Modified
12/06/2026 15:30
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
8.4 HIGH (v3) 8.4 HIGH (v4.0)
CISA KEV
No
CWE
CWE-346
CVSS vector

CVSS metrics

Description

Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
palo alto networks / idira identity browser extension cpe:2.3:a:palo_alto_networks:idira_identity_browser_extension:<26.8.1:*:*:*:*:*:*

References