CVE-2026-0274

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paloaltonetworks:cortex_xsiam_commvaultsecurityiq_marketplace:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xsoar_commvaultsecurityiq_marketplace:1.1.0:*:*:*:*:*:*:*

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de validación incorrecta de credenciales en la integración de CommvaultSecurityIQ para Cortex XSOAR y Cortex XSIAM permite a un atacante no autenticado acceder y modificar recursos protegidos.

10 Jul 2026, 16:49

Type Values Removed Values Added
First Time Paloaltonetworks
Paloaltonetworks cortex Xsiam Commvaultsecurityiq Marketplace
Paloaltonetworks cortex Xsoar Commvaultsecurityiq Marketplace
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:paloaltonetworks:cortex_xsiam_commvaultsecurityiq_marketplace:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xsoar_commvaultsecurityiq_marketplace:1.1.0:*:*:*:*:*:*:*
References () https://security.paloaltonetworks.com/CVE-2026-0274 - () https://security.paloaltonetworks.com/CVE-2026-0274 - Vendor Advisory

10 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 22:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-0274

Mitre link : CVE-2026-0274

CVE.ORG link : CVE-2026-0274


JSON object : View

Products Affected

paloaltonetworks

  • cortex_xsoar_commvaultsecurityiq_marketplace
  • cortex_xsiam_commvaultsecurityiq_marketplace
CWE
CWE-1390

Weak Authentication

NVD-CWE-noinfo