CVE-2026-0234

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paloaltonetworks:cortex_xsiam:*:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xsoar:*:*:*:*:*:*:*:*

History

07 Jul 2026, 18:08

Type Values Removed Values Added
First Time Paloaltonetworks
Paloaltonetworks cortex Xsoar
Paloaltonetworks cortex Xsiam
CPE cpe:2.3:a:paloaltonetworks:cortex_xsiam:*:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xsoar:*:*:*:*:*:*:*:*
References () https://security.paloaltonetworks.com/CVE-2026-0234 - () https://security.paloaltonetworks.com/CVE-2026-0234 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

13 Apr 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-13 08:16

Updated : 2026-07-07 18:08


NVD link : CVE-2026-0234

Mitre link : CVE-2026-0234

CVE.ORG link : CVE-2026-0234


JSON object : View

Products Affected

paloaltonetworks

  • cortex_xsiam
  • cortex_xsoar
CWE
CWE-347

Improper Verification of Cryptographic Signature