Home
MEDIUM: 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:M/U:AmberDefault status
unaffected
26.0.0 (custom) before 26.0.119
affected
Description
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue.
Problem types
CWE-306 Missing Authentication for Critical Function
Product status
26.0.0 (custom) before 26.0.119
Timeline
| 2025-05-14: | Initial Publication |
Credits
Bartosz Chałek
Piotr Kozowicz of CERT Team of ING Bank Slaski
References
security.paloaltonetworks.com/CVE-2025-0132