Description
An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.
Problem types
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
0.0.0 (custom) before v0.116.0
Timeline
| 2026-05-13: | Initial publication. |
Credits
Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.
References
security.paloaltonetworks.com/CVE-2026-0239