CVE-2026-0304: Cortex XDR Broker VM: Privilege Escalation Vulnerability (Severity: MEDIUM)

Published Sep 9, 2026
·
Updated

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

Affected Software

2 affected componentsFixes available
Cortex XDR Broker VM
Palo Alto Networks Cortex XDR Broker VM<32.0.52, =20.0.96
32.0.52

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 32.0.52
  2. Upgrade

    Upgrade Palo Alto Networks Cortex XDR Broker VM to a version that resolves this vulnerability.

    Fixed in 32.0.52
  3. Compensating control

    If automatic upgrades are not enabled for Cortex XDR Broker VM, enable automatic upgrades to ensure the latest security patches are installed. If automatic upgrades are enabled, no action is required at this time.

Event History

Sep 9, 2026
Advisory Published
via Palo Alto Networks·04:00 PM
Data Sourced
via Palo Alto Networks·04:00 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What access does an attacker need to exploit this issue?

The attacker must be an authenticated low-privileged user and also have man-in-the-middle access. The attack vector is adjacent network access rather than purely remote network access.

2

What is the potential impact if exploitation succeeds?

Successful exploitation allows execution of code with root privileges on the Cortex XDR Broker VM. This can affect confidentiality, integrity, and availability of the vulnerable VM.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203