CVE-2026-0274: Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration (Severity: HIGH)
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.2.0 - Upgrade
Upgrade
Cortex XSIAM CommvaultSecurityIQ Marketplaceto a version that resolves this vulnerability.Fixed in 1.2.0 - Upgrade
Upgrade
Cortex XSOAR CommvaultSecurityIQ Marketplaceto a version that resolves this vulnerability.Fixed in 1.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0274?
CVE-2026-0274 has a critical severity rating of 9.3, indicating a high level of risk.
How do I fix CVE-2026-0274?
Fixing CVE-2026-0274 requires updating your Cortex XSOAR or Cortex XSIAM CommvaultSecurityIQ integration to the latest version that addresses this vulnerability.
What impact does CVE-2026-0274 have on my systems?
CVE-2026-0274 allows unauthenticated attackers to access and modify protected resources, posing significant security risks.
Who is affected by CVE-2026-0274?
CVE-2026-0274 affects users of Palo Alto Networks Cortex XSOAR and Cortex XSIAM that utilize the CommvaultSecurityIQ integration.
Is there a workaround for CVE-2026-0274?
Currently, the recommended approach is to apply the available updates rather than relying on workarounds for CVE-2026-0274.