Home
HIGH: 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:RedDefault status
unaffected
1.5.0 (custom) before 1.5.52
affected
Default status
unaffected
1.5.0 (custom) before 1.5.52
affected
Description
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
Problem types
CWE-347 Improper Verification of Cryptographic Signature
Product status
1.5.0 (custom) before 1.5.52
1.5.0 (custom) before 1.5.52
Timeline
| 2026-04-08: | Initial Publication |
Credits
quinn
References
security.paloaltonetworks.com/CVE-2026-0234