CVE-2025-13762

MEDIUM

CyberArk Secure Web Sessions Extension <2.2.30305 - DoS

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: before 2.2.30305.

Scores

CVSS v4 4.8
EPSS 0.0012
EPSS Percentile 2.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
CyberArk/CyberArk Secure Web Sessions Extension < 2.2.30305
Published Nov 27, 2025
Tracked Since Feb 18, 2026