CVE-2025-4228: Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability (Severity: LOW)

Published Jun 11, 2025
·
Updated

An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the Broker VM and escalate their privileges to root.

Affected Software

1 affected componentFixes available
Palo Alto Networks Cortex XDR Broker VM<27.0.26, =
27.0.26

Remediation

Mitigation

No known workarounds or mitigations exist for this issue.

Information

This issue is fixed in Cortex XDR Broker VM 27.0.26, and all later Cortex XDR Broker VM versions. * If you enabled automatic upgrades for Broker VM, then no action is required at this time. * If you did not enable automatic upgrades, then we recommend that you do so for Broker VM to ensure that you always have the latest security patches installed in your software.

Event History

Jun 11, 2025
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 12, 2025
CVE Published
via MITRE·11:41 PM
Data Sourced
via MITRE·11:41 PM
DescriptionWeakness
Jun 13, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-4228?

CVE-2025-4228 has a high severity rating due to its potential for privilege escalation.

2

How do I fix CVE-2025-4228?

To fix CVE-2025-4228, update your Cortex XDR Broker VM to version 27.0.27 or later.

3

Who is affected by CVE-2025-4228?

CVE-2025-4228 affects authenticated administrative users of Palo Alto Networks Cortex XDR Broker VM versions up to 27.0.26.

4

What type of vulnerability is CVE-2025-4228?

CVE-2025-4228 is classified as an incorrect privilege assignment vulnerability.

5

Can CVE-2025-4228 be exploited remotely?

CVE-2025-4228 requires authenticated access to the system, so it is considered not a remote exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203