CVE-2026-0234: Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration (Severity: HIGH)
Published Apr 8, 2026
·Updated
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
Affected Software
4 affected componentsFixes available
Palo Alto Networks Cortex XSOAR Microsoft Teams Marketplace<1.5.52, =1.5.0
1.5.52
Palo Alto Networks Cortex XSIAM Microsoft Teams Marketplace<1.5.52, =1.5.0
1.5.52
Palo Alto Networks Cortex XSIAM>=1.5.0<1.5.52
Palo Alto Networks Cortex XSOAR>=1.5.0<1.5.52
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.5.52 - Upgrade
Upgrade
Cortex XSOAR Microsoft Teams Marketplace 1.5to a version that resolves this vulnerability.Fixed in 1.5.52 - Upgrade
Upgrade
Cortex XSIAM Microsoft Teams Marketplace 1.5to a version that resolves this vulnerability.Fixed in 1.5.52 - Compensating control
No known workarounds exist for this issue.
Event History
Apr 8, 2026
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 13, 2026
CVE Published
via MITRE·07:15 AM
Data Sourced
via MITRE·07:15 AM
DescriptionWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software