Identity CVE · Secrets managers
CVE-2025-49831CyberArk Conjur IAM authenticator bypass via network device
critical · CVSS 9.1
What broke
CVE-2025-49831 is the second IAM-authenticator bypass in the Cyata Conjur chain. A misconfigured network device in front of the authenticator lets an attacker satisfy the AWS identity check. CVSS 9.1. Fixed with CVE-2025-49827 in Conjur OSS 1.22.1 and Secrets Manager 13.6.1.
Why it matters
Two independent ways to fail the same authenticator is the story. Teams that patched only the regex bug and left the network path alone stayed exposed.
What to do
- Take the full Conjur/Secrets Manager upgrade, not a hotfix for 49827 alone.
- Review any appliance or proxy that sits in front of Conjur's IAM authenticator. If it can rewrite the STS conversation, it is in scope.
Sources
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.