PT-2025-29673 · Cyberark · Secrets Manager+1

Shahar Tal

+1

·

Published

2025-07-15

·

Updated

2025-09-12

·

CVE-2025-49831

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CyberArk Secrets Manager, Self-Hosted versions prior to 13.5.1 and 13.6.1 Conjur OSS versions prior to 1.22.1
Description An attacker with access to a misconfigured network device routing traffic from Secrets Manager to AWS can redirect authentication requests to a malicious server under their control. CyberArk believes that very few installations are susceptible to active exploitation.
Recommendations Update CyberArk Secrets Manager, Self-Hosted to version 13.5.1 or 13.6.1. Update Conjur OSS to version 1.22.1.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-49831
GHSA-952Q-MJRF-WP5J

Affected Products

Conjur Oss
Secrets Manager