Description
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
Published: 2026-09-10
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a privilege escalation flaw that allows an authenticated low‑privileged user who can intercept traffic (man‑in‑the‑middle) to execute arbitrary code with root privileges on the Broker VM. This weakness is identified as CWE‑88, which indicates a privilege escalation by bypassing intended access controls. Successful exploitation would grant the attacker full control over the Broker VM, compromising confidentiality, integrity, and availability of the monitoring solution.

Affected Systems

The flaw affects Palo Alto Networks Cortex XDR Broker VM deployments that are running a version prior to 32.0.52. All later releases contain the fix. The documentation does not enumerate specific sub‑versions, so any deployment below the stated version baseline should be considered vulnerable.

Risk and Exploitability

The CVSS score of 4.8 places this vulnerability in the medium severity range, and the EPSS score is not available, meaning there is no current statistical evidence of exploitation. The flaw is not listed in the CISA KEV catalog, but the likely attack vector requires a low‑privileged authenticated user with man‑in‑the‑middle access, so widespread exploitation is currently considered unlikely. Nonetheless, the potential for complete compromise of the Broker VM warrants immediate attention, and the user should apply the vendor’s patch cycle promptly.

Generated by OpenCVE AI on September 10, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Cortex XDR Broker VM to version 32.0.52 or later
  • Enable automatic upgrades so future patches are applied automatically
  • Restrict low‑privileged users’ network connectivity to prevent man‑in‑the‑middle attacks

Generated by OpenCVE AI on September 10, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
Title Cortex XDR Broker VM: Privilege Escalation Vulnerability
First Time appeared Palo Alto Networks
Palo Alto Networks cortex Xdr Broker Vm
Weaknesses CWE-88
CPEs cpe:2.3:a:palo_alto_networks:cortex_xdr_broker_vm:*:*:*:*:*:*:*:*
Vendors & Products Palo Alto Networks
Palo Alto Networks cortex Xdr Broker Vm
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/AU:N/R:U/V:D/RE:M/U:Amber'}


Subscriptions

Palo Alto Networks Cortex Xdr Broker Vm
cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2026-09-10T06:02:24.553Z

Reserved: 2025-11-03T20:45:02.858Z

Link: CVE-2026-0304

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T07:17:02.470

Modified: 2026-09-10T07:17:02.470

Link: CVE-2026-0304

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T07:30:07Z

Weaknesses
  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')