8.7
CVE-2026-0240
- EPSS 0.24%
- Veröffentlicht 13.05.2026 19:16:57
- Zuletzt bearbeitet 13.07.2026 13:56:26
- CVE-Watchlists
- Unerledigt
Trust Protection Foundation: Sensitive Information Disclosure Vulnerability
An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Paloaltonetworks ≫ Trust Protection Foundation Version >= 24.1.0 < 24.1.13
Paloaltonetworks ≫ Trust Protection Foundation Version >= 24.3.0 < 24.3.6
Paloaltonetworks ≫ Trust Protection Foundation Version >= 25.1.0 < 25.1.8
Paloaltonetworks ≫ Trust Protection Foundation Version >= 25.3.0 < 25.3.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.15 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.7 | 2.3 | 5.8 |
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
|
| psirt@paloaltonetworks.com | 4.5 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
|
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
https://security.paloaltonetworks.com/CVE-2026-0240