Description
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.
Published: 2026-07-09
Score: 1.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Broker VM that allows a locally authenticated user to gain root‑level privileges and perform actions as the root user. This flaw is associated with CWE‑269, a weakness in identity and access management. The impact is an elevation of privilege.

Affected Systems

The affected product is Palo Alto Networks Cortex XDR Broker VM. All versions prior to 31.0.58 are susceptible; the fix is incorporated in version 31.0.58 and all later Cortex XDR Broker VM versions.

Risk and Exploitability

The CVSS score of 1.1 classifies this vulnerability as low severity, and the EPSS score below 1% reflects a very low probability of exploitation. Because the vulnerability is not listed in the CISA KEV catalog, there is no evidence of active exploitation. The flaw requires a locally authenticated user to trigger the escalation, so an attacker would need valid credentials on the Broker VM. Even though the potential impact is full root privileges, the overall risk remains low due to the limited attack surface and low exploitation probability.

Generated by OpenCVE AI on July 29, 2026 at 11:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Cortex XDR Broker VM 31.0.58 or later to apply the vendor‑provided fix.
  • If automatic upgrades are not already enabled, enable automatic upgrades for Broker VM so future patches are installed automatically.
  • Continuously monitor Palo Alto Networks security advisories for Cortex XDR Broker VM to stay informed about additional fixes or mitigations.

Generated by OpenCVE AI on July 29, 2026 at 11:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.
Title Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability
First Time appeared Palo Alto Networks
Palo Alto Networks cortex Xdr Broker Vm
Weaknesses CWE-269
CPEs cpe:2.3:a:palo_alto_networks:cortex_xdr_broker_vm:*:*:*:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks cortex Xdr Broker Vm
References
Metrics cvssV4_0

{'score': 1.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Cortex Xdr Broker Vm
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-07-14T14:32:13.977Z

Reserved: 2025-11-03T20:44:35.481Z

Link: CVE-2026-0276

cve-icon Vulnrichment

Updated: 2026-07-10T14:20:28.324Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management