Palo Alto Networks Security Advisories / CVE-2026-0304

CVE-2026-0304 Cortex XDR Broker VM: Privilege Escalation Vulnerability

Urgency MODERATE

047910
Severity 4.8 · MEDIUM
Exploit Maturity UNREPORTED
Response Effort MODERATE
Recovery USER
Value Density DIFFUSE
Attack Vector ADJACENT
Attack Complexity LOW
Attack Requirements PRESENT
Automatable NO
User Interaction NONE
Product Confidentiality HIGH
Product Integrity HIGH
Product Availability HIGH
Privileges Required LOW
Subsequent Confidentiality LOW
Subsequent Integrity LOW
Subsequent Availability LOW

Description

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

Product Status

VersionsAffectedUnaffected
Cortex XDR Broker VM 20.0.96< 32.0.52>= 32.0.52

Required Configuration for Exposure

No special configuration is required to be affected by this issue on brokers that process cloud-delivered mount actions.

Severity: MEDIUM, Suggested Urgency: MODERATE


MEDIUM - CVSS-BT: 4.8 /CVSS-B: 7.5 (CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/AU:N/R:U/V:D/RE:M/U:Amber)

Exploitation Status

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Weakness Type and Impact

CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

CAPEC-126 Path Traversal

Solution

This issue is fixed in Cortex XDR Broker VM 32.0.52, and all later Cortex XDR Broker VM versions.

Workarounds and Mitigations

No known workarounds exist for this issue.

Acknowledgments

Palo Alto Networks thanks internal security research teams for discovering and reporting this issue.

CPE Applicability

Timeline

Initial Publication
© 2026 Palo Alto Networks, Inc. All rights reserved.