PT-2025-29614 · Cyberark · Conjur+1

·

CVE-2025-49829

·

Published

2025-07-15

·

Updated

2025-08-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Conjur Secrets Manager, Self-Hosted versions prior to 13.5.1 and 13.6.1 Conjur OSS versions prior to 1.22.1
Description Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authenticated attackers to inject resources into the database and bypass permission checks.
Recommendations Update Conjur Secrets Manager, Self-Hosted to version 13.5.1 or 13.6.1. Update Conjur OSS to version 1.22.1.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49829
GHSA-9W76-M74G-4C2R

Affected Products

Conjur
Conjur Oss