Injection Vulnerability in Secrets Management Tool by CyberArk
CVE-2025-49829
What is CVE-2025-49829?
CyberArk's Secrets Manager, specifically in its Self-Hosted variant, contains a vulnerability that allows authenticated attackers to perform unauthorized database resource injection. This security flaw is caused by missing validation checks within the application, enabling adversaries to bypass established permission protocols. This issue affects older versions of Secrets Manager, Self-Hosted and Conjur OSS, with patched versions available in 13.5.1, 13.6.1, and 1.22.1, respectively.
Affected Version(s)
conjur Conjur OSS < 1.22.1 < Conjur OSS 1.22.1
conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) < 13.5.1 < Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.5.1
conjur Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) = 13.6 = Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.6