Start with Identity
Identity CVE · Secrets managers

CVE-2025-49828CyberArk Conjur RCE via Ruby template injection

high · CVSS 8.6
Product: CyberArk Conjur / Secrets ManagerVendor: CyberArkDisclosed: 2025-07-15Status: PatchedNVD ↗

What broke

Conjur interpolated attacker-influenced data into a Ruby template and executed it. CVSS 8.6. After CVE-2025-49827 or CVE-2025-49831 gets you in, this is the RCE. Fixed in Conjur OSS 1.22.1 and Secrets Manager 13.6.1.

Why it matters

Secrets-manager RCE is game over for every workload secret, every rotation credential, and often the cloud IAM role the manager itself holds. Identity teams own this box even when AppSec files the ticket.

What to do

  • Patch, then rotate. Assume every secret Conjur could read was readable by the attacker during the vulnerable window if the authenticator was reachable.
  • Ban user-controlled template rendering in any secrets or policy engine. The same class showed up in SailPoint transform templates.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.