Known Vulnerabilities for Identity by Cyberark
Listed below are 2 of the newest known vulnerabilities associated with "Identity" by "Cyberark".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41299 json | OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only prove... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-41298 json | OpenClaw before 2026.4.2 fails to enforce write scopes on the POST /sessions/:sessionKey/kill endpoint in identity-bearing HT... | Not Provided | 2026-04-21 | 2026-04-20 |
| CVE-2026-41166 json | OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.1, a user who has `write:admin` in one Keyclo... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2026-40865 json | Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in t... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40683 json | In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when ... | Not Provided | 2026-04-14 | 2026-04-14 |
| CVE-2026-40574 json | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Prior to 7.15.2, an authorization bypass... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40285 json | WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/mem... | Not Provided | 2026-04-17 | 2026-04-20 |
| CVE-2026-40264 json | OpenBao is an open source identity-based secrets management system. OpenBao's namespaces provide multi-tenant separation. Pri... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40193 json | maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the auth.ld... | Not Provided | 2026-04-16 | 2026-04-16 |
| CVE-2026-40070 json | BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certificat... | Not Provided | 2026-04-09 | 2026-04-13 |