CVE-2026-0240: Trust Protection Foundation: Sensitive Information Disclosure Vulnerability (Severity: MEDIUM)
An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 25.3.3Fixed in 25.1.8Fixed in 24.3.6Fixed in 24.1.13 - Upgrade
Upgrade
Trust Protection Foundationto a version that resolves this vulnerability.Fixed in 24.1.13 - Upgrade
Upgrade
Trust Protection Foundationto a version that resolves this vulnerability.Fixed in 24.3.6 - Upgrade
Upgrade
Trust Protection Foundationto a version that resolves this vulnerability.Fixed in 25.1.8 - Upgrade
Upgrade
Trust Protection Foundationto a version that resolves this vulnerability.Fixed in 25.3.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0240?
The severity of CVE-2026-0240 is high with a CVSS score of 7.4.
How do I fix CVE-2026-0240?
To fix CVE-2026-0240, upgrade to Trust Protection Foundation versions 25.3.3 or later, 25.1.8 or later, or 24.3.6 or later.
What type of vulnerability is CVE-2026-0240?
CVE-2026-0240 is an information disclosure vulnerability.
Who can exploit CVE-2026-0240?
An authenticated attacker can exploit CVE-2026-0240 to obtain sensitive information from the server's vault.
What are the potential impacts of CVE-2026-0240?
Successful exploitation of CVE-2026-0240 allows an attacker to impersonate users and modify configurations.