# CyberArk Conjur IAM authenticator bypass via malformed regex

Source: https://startwithidentity.com/cves/cve-2025-49827/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[CyberArk Conjur](https://startwithidentity.com/vendors/secrets/cyberark-conjur/) authenticates AWS workloads by validating an STS identity. A malformed regex in that authenticator redirected the validation to a server the attacker controlled (CWE-807, reliance on untrusted inputs in a security decision). CVSS 9.1. Cyata disclosed five Conjur CVEs at Black Hat USA 2025 (published 19 June / 15 July 2025). Chained, they become unauthenticated RCE. Fixed in Conjur OSS 1.22.1 and Secrets Manager 13.5.1 / 13.6.1. No known in-the-wild exploitation at disclosure.

## Why it matters

A secrets manager is an [identity provider](https://startwithidentity.com/glossary/identity-provider/) for machines. Bypass the IAM authenticator and you do not steal one secret. You become every workload that Conjur would have handed credentials to. This is the secrets-plane equivalent of [CVE-2025-55241](https://startwithidentity.com/cves/cve-2025-55241/).

## What to do

- Upgrade Conjur OSS to 1.22.1+ or Secrets Manager to 13.6.1+. Take all five CVEs in one change.
- Rotate every secret Conjur held. A bypass means you cannot trust what was checked out.
- Pin the STS endpoint. Do not let authenticator config supply the host you validate against.

## After you patch

A vault compromise is not one credential, it is every credential the vault held or could issue.

- **Rotate everything in scope**, including secrets the vault issued dynamically during the exposure window, because a lease that was valid then may still be valid now.
- **Revoke active leases and tokens**, then review the audit device log for reads you cannot attribute to a known workload.
- **Rotate the vault's own credentials**: unseal or recovery keys, root tokens, and any authentication backend configuration that could be used to re-enter.
- **Rotate downstream credentials the vault brokered**, cloud roles, database users, and PKI certificates, since the point of the vault is that it can mint them. See [secrets rotation](https://startwithidentity.com/glossary/secrets-rotation/) and [what is secrets management](https://startwithidentity.com/guides/fundamentals/what-is-secrets-management/).

## Sources

- [NVD: CVE-2025-49827](https://nvd.nist.gov/vuln/detail/CVE-2025-49827)
- Cyata, Black Hat USA 2025, CyberArk Conjur chain
