Description
A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
1.0.0 (custom) before 26.100.3
Timeline
| 2025-04-09: | Initial Publication |
Credits
Bartosz Chałek
Piotr Kozowicz of CERT Team of ING Bank Slaski
References
security.paloaltonetworks.com/CVE-2025-0119