Remote Code Execution Vulnerability in Conjur Secrets Manager by CyberArk
CVE-2025-49828

8.6HIGH

Key Information:

Vendor

Cyberark

Status
Vendor
CVE Published:
15 July 2025

What is CVE-2025-49828?

A remote code execution vulnerability exists in Conjur, affecting versions 1.19.5 to 1.21.1 of Conjur OSS and versions 13.1 to 13.4.1 of Secrets Manager, Self-Hosted. An authenticated attacker may exploit this vulnerability by injecting malicious secrets or templates into the Secrets Manager, Self-Hosted database. This can be done through an exposed API endpoint, allowing the attacker to execute arbitrary Ruby code within the Secrets Manager process. CyberArk has released versions 1.21.2 for Conjur OSS and 13.5 for Secrets Manager, Self-Hosted, which address this issue.

Affected Version(s)

conjur Conjur OSS >= 1.20.1, < 1.21.2 < Conjur OSS 1.20.1, 1.21.2

conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) >= 13.1, < 13.5 < Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1, 13.5

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49828 : Remote Code Execution Vulnerability in Conjur Secrets Manager by CyberArk