Error PAM-UI-1005 when terminating connections as Session Manager in Privileged Access Manager
search cancel

Error PAM-UI-1005 when terminating connections as Session Manager in Privileged Access Manager

book

Article ID: 454391

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Users with the built-in Session Manager role in Privileged Access Manager (PAM) encounter an "Error: PAM-UI-1005: Authorization failed. User does not have permission for this action" when attempting to terminate active connections via the GUI or REST API. This issue affects PAM from version 4.2.3 to 4.3.2 and occurs even when the role is scoped to "All Users" and "All Devices."

Environment

  • Privileged Access Manager (PAM) 4.2.3, 4.3.0, 4.3.1,4,3,2
  • Role: Session Manager (built-in)
  • Symptom: HTTP 403 Forbidden / PAM-UI-1005

Cause

This is a known product defect (DE687793). The Session Manager role incorrectly requires "Monitor" or "Service Manager" privileges instead of the expected "Session Read" or "Session Manage" rights to execute the DELETE operation on active connections.

Resolution

This defect will be fixed in PAM release 4.3.3 and higher (4.3.3 not published as of September 2026). 

For PAM 4.3.1 or 4.3.2 environments Contact Broadcom Support to check if possible to obtain the patch