CVE-2026-0270

Severity CVSS v4.0:
MEDIUM
Type:
CWE-22 Path Traversal
Publication date:
10/06/2026
Last modified:
23/07/2026

Description

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:paloaltonetworks:cortex_xsoar:*:*:*:*:*:*:*:* 8.10.0 (including) 8.13.0.11 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*