CyberArk Privileged Access Manager Self-Hosted LDAP Mapping Privilege Escalation Vulnerability

Vulnerability

A vulnerability in the Password Vault Web Access (PVWA) component of CyberArk Privileged Access Manager Self-Hosted, prior to version 14.4, allows for potentially elevated privileges through improper handling of LDAP mapping. This issue could be exploited by manipulating group mapping parameters, leading to unauthorized access or privileges.

Impact

Exploitation of this vulnerability could result in unauthorized elevation of privileges within the application, allowing users to gain access to resources or functionalities that should be restricted.

Remediation

Users are advised to upgrade to CyberArk Privileged Access Manager Self-Hosted version 14.4 or later, where this vulnerability has been addressed.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.