CVE-2026-0231Disclosure

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cortex UI and modifying any configuration setting.  The attacker must have network access to the Broker VM to exploit this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-497

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-11); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-19: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-19: 103-1103-1203-19
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-121
Disclosure1
2026-03-191
Patch1
Full discourse3 posts
  • iototsecnews@iototsecnews
    Patch

    Palo Alto Cortex XDR Broker の脆弱性 CVE-2026-0231 が FIX:機密情報の漏洩/改竄の恐れ https://iototsecnews.jp/2026/03/12/palo-alto-cortex-xdr-broker-vulnerability-exposes-systems-to-sensitive-information-theft-and-modification/ Palo Alto Networks の、オンプレミスとクラウドを繋ぐ重要コンポーネントである Cortex XDR Broker VM において、機密情報の漏洩や設定の改竄などを許す、深刻な脆弱性 CVE-2026-0231 (Medium) が発生しました。この問題の原因は、管理機能の処理不備により、機密性の高いシステム情報が露出してしまう、情報の不適切な公開 (CWE-497) にあります。 この脆弱性は、管理者が利用する Live Terminal セッションを介して発動します。このセッションを起動する認証済みのユーザーは、本来保護されているはずのシステム設定や高機密データへのアクセス/変更が可能になり、セキュリティ・アプライアンスとしての整合性を損なうリスクを引き起こします。ご利用のチームは、ご注意ください。 #CortexXDRBroker #CVE20260231 #PaloAlto #Vulnerability

    Post summary

    The post announces CVE‑2026‑0231, a medium‑severity flaw in Palo Alto’s Cortex XDR Broker that lets authenticated administrators leak or alter system data, and confirms that a fix is available.

    01000158
    484 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0231 An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggerin… https://www.cve.org/CVERecord?id=CVE-2026-0231

    Post summary

    The text provides a brief disclosure of CVE‑2026‑0231, describing it as an information‑disclosure flaw in Palo Alto Networks Cortex XDR® Broker VM that lets authenticated users obtain and modify sensitive data.

    00000213
    56.7K followersView on X
  • まっちゃだいふく@ripjyr
    Disclosure

    Paloaltoの脆弱性情報 「CVE-2026-0231 Cortex XDR Broker VM: Sensitive Information Disclosure Vulnerability (Severity: MEDIUM)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0231

    Post summary

    A Palo Alto Networks advisory for CVE‑2026‑0231 has been released, describing a sensitive information disclosure vulnerability in Cortex XDR Broker VM with medium severity; no PoC or exploitation details are provided.

    00000342
    8.6K followersView on X

Explore more