An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
References
| Link | Resource |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0234 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
07 Jul 2026, 18:08
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Paloaltonetworks
Paloaltonetworks cortex Xsoar Paloaltonetworks cortex Xsiam |
|
| CPE | cpe:2.3:a:paloaltonetworks:cortex_xsiam:*:*:*:*:*:*:*:* cpe:2.3:a:paloaltonetworks:cortex_xsoar:*:*:*:*:*:*:*:* |
|
| References | () https://security.paloaltonetworks.com/CVE-2026-0234 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
13 Apr 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-13 08:16
Updated : 2026-07-07 18:08
NVD link : CVE-2026-0234
Mitre link : CVE-2026-0234
CVE.ORG link : CVE-2026-0234
JSON object : View
Products Affected
paloaltonetworks
- cortex_xsiam
- cortex_xsoar
CWE
CWE-347
Improper Verification of Cryptographic Signature
