← Back

CVE-2026-0270

nvd nist
Published: Jun 10, 2026Modified: Jul 10, 2026

JSON object

Loading...
4.8
Vector
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Amber
Show more
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:AmberShow less
Source: psirt@paloaltonetworks.com (Secondary)

Description

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.

Affected (1)

Cortex Xsoar
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 8.10.0 to 8.13.0.11
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (2)

Source: psirt@paloaltonetworks.com
Third Party AdvisoryUS Government Resource
Source: psirt@paloaltonetworks.com
Vendor Advisory

Timeline

No history available yet.