CVE-2026-45173: Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure
Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21
Metrics
- CVSS v4.0
- 8.4
- Severity
- HIGH
- Fixed in
- 26.8.1
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An origin validation failure in the Idira Identity Browser Extension (Chrome, Firefox, and Edge builds, versions 26.0.0 through 26.8.1) allows a remote attacker to trigger unauthorized application interaction within an authenticated browser session. The attack is delivered over the network and requires no authentication on the attacker's part, but does require the victim to visit a specially crafted webpage. Successful exploitation lets an attacker read sensitive data and manipulate application state within the context of the victim's authenticated session. A patched-image rebuild at version 26.8.1 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-45173 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against images in customer registries, CI/CD pipelines, and custom-built images that bundle the Idira Identity Browser Extension.
AvailableHarborGuard is capable of scoring this CVE at CVSS 8.4 (HIGH) and weighting that score against each environment's compliance policy to determine urgency; findings are routable to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild at version 26.8.1 is available on HarborGuard for any environment running an affected version of the Idira Identity Browser Extension. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the malicious payload over the network; the victim's browser must be able to reach the attacker-controlled webpage.
- AuthenticationNot required
No credentials or account on the target system are needed; the attacker requires no prior authentication.
- Victim interactionRequired
The victim must navigate to a specially crafted webpage, requiring a social-engineering step to lure the authenticated user to the attacker-controlled URL.
- Attack complexityDetail
Attack complexity is low; the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.
Blast Radius
- Reads sensitive data accessible within the authenticated browser session, including stored credentials or session tokens managed by the Idira extension.
- Modifies application interaction parameters within the authenticated session context, potentially altering in-progress workflows or authorization state.
- Affects both the local browser session scope and downstream connected systems, as the CVSS vector indicates high impact to both victim and subsequent system confidentiality and integrity.
How HarborGuard Handles This
Available on HarborGuard: detection of this CVE is matched against customer images the moment the advisory is ingested. For environments running Idira Identity Browser Extension versions 26.0.0 through below 26.8.1, a rebuilt image at the fixed version 26.8.1 is available. Where compliance policy permits auto-remediation, HarborGuard rebuilds the image, runs regression tests, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Customers not yet on auto-remediation should prioritize manual upgrade to 26.8.1 and, in the interim, consider network-policy controls that restrict which origins the extension is permitted to load content from, reducing the surface available to a would-be attacker.
Fix available
- CyberArk Software, a Palo Alto Networks Company / Identity Browser Extensions< 26.8.1 (from 26.0.0)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N/U:Amber