Description
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
8.13 (custom) before 8.13.0.11
8.12.0 (custom)
8.11.0 (custom)
8.10.0 (custom)
6.14.0 (custom)
6.13.0 (custom)
6.12.0 (custom)
Timeline
| 2026-06-10: | Initial publication |
Credits
Palo Alto Networks thanks the internal security team for discovering and reporting this issue.
References
security.paloaltonetworks.com/CVE-2026-0270
nvd.nist.gov/vuln/detail/CVE-2007-4559 (CVE-2007-4559: Python tarfile module path traversal)