Privilege Escalation in Palo Alto Cortex XDR Broker VM via MitM
CVE-2026-0304 Published on September 10, 2026
Cortex XDR Broker VM: Privilege Escalation Vulnerability
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
Vulnerability Analysis
Timeline
Initial Publication
Weakness Type
What is an Argument Injection Vulnerability?
The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CVE-2026-0304 has been classified to as an Argument Injection vulnerability or weakness.
Products Associated with CVE-2026-0304
Want to know whenever a new CVE is published for Palo Alto Networks Cortex Xdr Broker Vm? stack.watch will email you.
Affected Versions
Palo Alto Networks Cortex XDR Broker VM:- Version 20.0.96 and below 32.0.52 is affected.