Palo Alto Networks Security Advisories / CVE-2026-0241

CVE-2026-0241 Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities

Urgency MODERATE

047910
Severity 5.1 · MEDIUM
Exploit Maturity UNREPORTED
Response Effort MODERATE
Recovery USER
Value Density DIFFUSE
Attack Vector ADJACENT
Attack Complexity LOW
Attack Requirements NONE
Automatable NO
User Interaction NONE
Product Confidentiality LOW
Product Integrity LOW
Product Availability HIGH
Privileges Required NONE
Subsequent Confidentiality LOW
Subsequent Integrity LOW
Subsequent Availability NONE

Description

Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.

Product Status

VersionsAffectedUnaffected
Trust Protection Foundation 25.3.0< 25.3.3
>= 25.3.3
Trust Protection Foundation 25.1.0< 25.1.8
>= 25.1.8
Trust Protection Foundation 24.3.0< 24.3.6
>= 24.3.6
Trust Protection Foundation 24.1.0< 24.1.13
>= 24.1.13

Required Configuration for Exposure

No specific configuration is required for exposure to this vulnerability.

Severity: MEDIUM, Suggested Urgency: MODERATE

CVSS-BT: 5.1 / CVSS-B: 7.2 (CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)

Exploitation Status

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Weakness Type and Impact

CWE-754 Improper Check for Unusual or Exceptional Conditions

CAPEC-122 Privilege Abuse

Solution

VersionMinor VersionSuggested Solution
Trust Protection Foundation 25.325.3.0 through 25.3.2Upgrade to 25.3.3 or later.
Trust Protection Foundation 25.125.1.0 through 25.1.7Upgrade to 25.1.8 or later.
Trust Protection Foundation 24.324.3.0 through 24.3.5Upgrade to 24.3.6 or later.
Trust Protection Foundation 24.124.1.0 through 24.1.12Upgrade to 24.1.13 or later.

Workarounds and Mitigations

No known workarounds exist for this issue.

Acknowledgments

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.

CPE Applicability

Timeline

Initial publication.
© 2026 Palo Alto Networks, Inc. All rights reserved.