Known Vulnerabilities for PAM SH Vault by CyberArk Software A Palo Alto Networks Company
Listed below are 10 of the newest known vulnerabilities associated with "PAM SH Vault" by "CyberArk Software A Palo Alto Networks Company".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65710 json | sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLIC... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-65709 json | sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows AP... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-65708 json | sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attac... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-62825 json | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | Not Provided | 2026-07-24 | 2026-07-25 |
| CVE-2026-60104 json | Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the au... | Not Provided | 2026-07-08 | 2026-07-14 |
| CVE-2026-55994 json | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vul... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-55993 json | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor, Server-Side Request Forgery (SSRF) vul... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-55100 json | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates un... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-54725 json | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1... | Not Provided | 2026-07-31 | 2026-07-31 |
| CVE-2026-48892 json | The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BA... | Not Provided | 2026-07-07 | 2026-07-07 |