<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Access Manager - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/access-manager/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 06 Aug 2026 15:19:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/access-manager/feed.xml" rel="self" type="application/rss+xml"/><item><title>Multiple Security Vulnerabilities in Wallix Access Manager and Bastion</title><link>https://feed.craftedsignal.io/briefs/2026-08-wallix-vulnerabilities/</link><pubDate>Thu, 06 Aug 2026 15:19:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-wallix-vulnerabilities/</guid><description>Multiple vulnerabilities in Wallix Access Manager and Bastion products allow for unauthorized privilege escalation and security policy bypass.</description><content:encoded><![CDATA[<p>The French National Cybersecurity Agency (ANSSI) has published an advisory regarding multiple vulnerabilities identified in Wallix Access Manager and Bastion products. These flaws, detailed in the Wallix security bulletin from July 20, 2026, enable an attacker to perform privilege escalation or bypass security policy enforcement mechanisms. The vulnerabilities specifically affect deployments of Wallix Access Manager utilizing SAML federation, as well as specific version branches of the Wallix Bastion. Because these products serve as centralized gateways for privileged access, successful exploitation could provide an attacker with unauthorized administrative control over managed assets. Defenders are urged to audit version numbers against the affected ranges and apply vendor-provided patches immediately.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows unauthorized actors to escalate privileges within the Wallix management environment and circumvent security policies designed to restrict access. This poses a high risk to organizations relying on Wallix for privileged account management and session recording, as it could allow attackers to bypass audit controls or gain administrative access to critical infrastructure managed by the bastion.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update Wallix Access Manager to version 5.1.10, 5.2.7, or 6.0.4 or later, depending on the current branch.</li>
<li>Update Wallix Bastion to version 12.3.7 or 12.4.1 or later.</li>
<li>Review configurations of SAML federation in Access Manager to ensure security controls are correctly enforced until patching is complete.</li>
<li>Monitor logs for unusual administrative login activity or unauthorized configuration changes on Wallix appliances.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>privilege-escalation</category><category>authentication-bypass</category><category>informational</category></item></channel></rss>