CVE-2026-45173
Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21
| CWE | CWE-346 |
| Vendor | cyberark software, a palo alto networks company |
| Product | identity browser extensions |
| Published | Jun 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for cyberark software, a palo alto networks company identity browser extensions
Be the first to know when new unknown vulnerabilities affecting cyberark software, a palo alto networks company identity browser extensions are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
CyberArk Software, a Palo Alto Networks Company / Identity Browser Extensions
26.0.0 < 26.8.1
References
Credits
Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue