CVE-2026-0304: Cortex XDR Broker VM: Privilege Escalation Vulnerability (Severity: MEDIUM)
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 32.0.52 - Upgrade
Upgrade
Palo Alto Networks Cortex XDR Broker VMto a version that resolves this vulnerability.Fixed in 32.0.52 - Compensating control
If automatic upgrades are not enabled for Cortex XDR Broker VM, enable automatic upgrades to ensure the latest security patches are installed. If automatic upgrades are enabled, no action is required at this time.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be an authenticated low-privileged user and also have man-in-the-middle access. The attack vector is adjacent network access rather than purely remote network access.
What is the potential impact if exploitation succeeds?
Successful exploitation allows execution of code with root privileges on the Cortex XDR Broker VM. This can affect confidentiality, integrity, and availability of the vulnerable VM.