CVE-2026-0270: Cortex XSOAR: Path Traversal Vulnerability (Severity: MEDIUM)
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.13.0.11 - Upgrade
Upgrade
Palo Alto Networks Cortex XSOAR (engine)to a version that resolves this vulnerability.Fixed in 8.13.0.11
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0270?
CVE-2026-0270 has a high severity rating of 7.5 on the CVSS scale.
How do I fix CVE-2026-0270?
To mitigate CVE-2026-0270, upgrade to Cortex XSOAR version 8.13.0.11 or later.
What type of vulnerability is CVE-2026-0270?
CVE-2026-0270 is a path traversal vulnerability affecting Palo Alto Networks Cortex XSOAR.
Who is affected by CVE-2026-0270?
CVE-2026-0270 affects users of Palo Alto Networks Cortex XSOAR running on Linux.
Can CVE-2026-0270 be exploited remotely?
Yes, CVE-2026-0270 can be exploited by an unauthenticated attacker on an adjacent network through a man-in-the-middle attack.