CVE-2026-0231
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
11/03/2026
Last modified:
12/03/2026
Description
An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cortex UI and modifying any configuration setting. <br />
The attacker must have network access to the Broker VM to exploit this issue.



