CVE-2025-49831 is a critical authentication bypass vulnerability affecting CyberArk Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1, and Conjur OSS prior to version 1.22.1. An attacker can reroute authentication requests to a malicious server if traffic from Secrets Manager to AWS is routed through a misconfigured network device. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While CyberArk believes active exploitation is rare, there is no public exploit code, and it is not listed in CISA's KEV catalog, community discussion and media coverage indicate awareness of this critical flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.22.1CPE matchmatch criteria | cpe:2.3:a:cyberark:conjur:*:*:*:*:open_source:*:*:* | ||
< 13.5.1CPE matchmatch criteria | cpe:2.3:a:cyberark:conjur:*:*:*:*:enterprise:*:*:* | ||
13.6CPE matchmatch criteria | cpe:2.3:a:cyberark:conjur:13.6:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.