CVE-2025-49829

MEDIUM

Conjur < 1.22.1 and Secrets Manager, Self-Hosted < 13.5.1 - Authenticated Resource Injection and Permission Bypass

Title source: llm
STIX 2.1

Description

Conjur provides secrets management and application identity for infrastructure. Missing validations in Secrets Manager, Self-Hosted allows authenticated attackers to inject resources into the database and to bypass permission checks. This issue affects Secrets Manager, Self-Hosted (formerly Conjur Enterprise) prior to versions 13.5.1 and 13.6.1 and Conjur OSS prior to version 1.22.1. Conjur OSS version 1.22.1 and Secrets Manager, Self-Hosted versions 13.5.1 and 13.6.1 fix the issue.

Scores

CVSS v3 6.5
EPSS 0.0037
EPSS Percentile 29.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
cyberark/conjur 13.6
cyberark/conjur < 1.22.1
cyberark/conjur < 13.5.1
Published Jul 15, 2025
Tracked Since Feb 18, 2026