CVE-2026-45173

Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure

Severity
High 8.4
CVSS 4.0
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.002
10.8th percentile
Discovered by
Vendor
Vendor-published field
Published
Jun 11, 2026
Assigned by palo_alto

Description

Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21

Weakness: CWE-346

Affected products

Vendor Product Category Matched by
Palo Alto Networks CyberArk Identity Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • CyberArk Software, a Palo Alto Networks Company · Identity Browser Extensions

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue

Something wrong here?