Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. CyberArk/
  3. Secrets Manager (Conjur)

Secrets Manager (Conjur)

SecretsAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 37 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~47 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Secrets management for apps and CI/CD.

by CyberArk · cyberark.com

Known CVEs (37)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-45169 ↗HIGH 8.62026

    Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenario…

  • CVE-2026-45170 ↗HIGH 8.82026

    Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bullet…

  • CVE-2026-45174 ↗HIGH 7.82026

    Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19

  • CVE-2026-45173 ↗MEDIUM 6.52026

    Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated u…

  • CVE-2026-45172 ↗HIGH 8.82026

    Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially exec…

  • CVE-2026-45171 ↗HIGH 8.82026

    Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privi…

  • CVE-2026-45175 ↗HIGH 7.82026

    Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security co…

  • CVE-2026-45178 ↗HIGH 8.12026

    Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentia…

  • CVE-2026-45177 ↗CRITICAL 9.12026

    Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting…

  • CVE-2026-45176 ↗HIGH 7.82026

    Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulati…

  • CVE-2026-2914 ↗HIGH 7.82026

    CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized privilege elevation leveraging CyberArk elevation dialogs

  • CVE-2025-66374 ↗HIGH 7.82026

    CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task.

  • CVE-2025-13762 ↗2025

    Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk…

  • CVE-2025-49831 ↗CRITICAL 9.82025

    An attacker of Secrets Manager, Self-Hosted installations that route traffic from Secrets Manager to AWS through a misconfigured network device can reroute authentication requests to a malicious serve…

  • CVE-2024-57967 ↗MEDIUM 4.22025

    PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 has potentially elevated privileges in LDAP mapping.

  • CVE-2024-54840 ↗MEDIUM 4.22025

    PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.

  • CVE-2024-42340 ↗HIGH 8.32024

    CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security

  • CVE-2024-42339 ↗MEDIUM 4.32024

    CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

  • CVE-2024-42338 ↗MEDIUM 4.32024

    CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

  • CVE-2024-42337 ↗MEDIUM 4.32024

    CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

  • …and 17 more

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Identity & Access Management products

see all →
  • 1Password Extended Access Management · 1Password
  • AD Guardian Cloud · CionSystems
  • ARCON Privileged Access Management · ARCON
  • Abbey Labs · Abbey Labs
  • Aceiss · Aceiss
  • Active Directory Permissions Analyzer · Paramount Defenses
  • Adaptive MFA · Okta
  • Adaxes · softerra adaxes