Privilege Escalation in Palo Alto Cortex XDR Broker VM via MitM
CVE-2026-0304 Published on September 10, 2026

Cortex XDR Broker VM: Privilege Escalation Vulnerability
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

Vendor Advisory NVD

Vulnerability Analysis

Attack Vector:
ADJACENT
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE

Timeline

Initial Publication

Weakness Type

What is an Argument Injection Vulnerability?

The software constructs a string for a command to executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

CVE-2026-0304 has been classified to as an Argument Injection vulnerability or weakness.


Products Associated with CVE-2026-0304

Want to know whenever a new CVE is published for Palo Alto Networks Cortex Xdr Broker Vm? stack.watch will email you.

 

Affected Versions

Palo Alto Networks Cortex XDR Broker VM: