CVE-2026-0238: Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields (Severity: LOW)
A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 30.0.24 - Upgrade
Upgrade
Palo Alto Networks Broker VMto a version that resolves this vulnerability.Fixed in 30.0.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0238?
The severity of CVE-2026-0238 is classified as low.
What causes CVE-2026-0238?
CVE-2026-0238 is caused by improper input validation in certain fields of the Broker VM Certificate and Key.
How do I fix CVE-2026-0238?
To fix CVE-2026-0238, ensure that input validation mechanisms are properly implemented to sanitize user input in the affected fields.
Who is affected by CVE-2026-0238?
CVE-2026-0238 affects authenticated administrators using Palo Alto Networks Broker VM.
What can an attacker gain from CVE-2026-0238?
An attacker may exploit CVE-2026-0238 to inject arbitrary content into the Broker VM, potentially compromising its functionality.