Impact
A privilege escalation vulnerability exists in Palo Alto Networks Cortex XDR Broker VM that allows a locally authenticated user to gain root‑level privileges and perform actions as the root user. This flaw is associated with CWE‑269, a weakness in identity and access management. The impact is an elevation of privilege.
Affected Systems
The affected product is Palo Alto Networks Cortex XDR Broker VM. All versions prior to 31.0.58 are susceptible; the fix is incorporated in version 31.0.58 and all later Cortex XDR Broker VM versions.
Risk and Exploitability
The CVSS score of 1.1 classifies this vulnerability as low severity, and the EPSS score below 1% reflects a very low probability of exploitation. Because the vulnerability is not listed in the CISA KEV catalog, there is no evidence of active exploitation. The flaw requires a locally authenticated user to trigger the escalation, so an attacker would need valid credentials on the Broker VM. Even though the potential impact is full root privileges, the overall risk remains low due to the limited attack surface and low exploitation probability.
OpenCVE Enrichment