← Back

CVE-2026-0240

nvd nist
Published: May 13, 2026Modified: Jul 13, 2026

JSON object

Loading...
4.5
Vector
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
Show more
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:AmberShow less
Source: psirt@paloaltonetworks.com (Secondary)

Description

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

Affected (4)

Trust Protection Foundation
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Paloaltonetworks
From 24.1.0 to 24.1.13
From 24.3.0 to 24.3.6
From 25.1.0 to 25.1.8
From 25.3.0 to 25.3.3

References (1)

Source: psirt@paloaltonetworks.com
Vendor Advisory

Timeline

No history available yet.