← All Advisories

Palo Alto Networks Cortex XSOAR Path Traversal Scores 7.5

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-0270

Key Details

CVECVE-2026-0270
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is adjacent; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsPalo Alto Networks Cortex XSOAR
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
Exploitation prediction (EPSS)0.20% probability of exploitation in the next 30 days (9% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksCortex XSOAR
SubsystemsGeneral OT
SectorsMultiple

What to Know

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.

What to Do

Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0270
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0270
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0270