CVE-2026-0233 PUBLISHED

Autonomous Digital Experience Manager: Improper validation of ADEM certificate

Assigner: palo_alto
Reserved: 03.11.2025 Published: 13.04.2026 Updated: 13.04.2026

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Green
CVSS Score: 2

Product Status

Vendor Palo Alto Networks
Product Autonomous Digital Experience Manager
Versions Default: unaffected
  • affected from 5.10.0 to 5.10.14 (excl.)

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Credits

  • David Fischer with OBI finder

References

Problem Types

  • CWE-295: Improper Certificate Validation CWE

Impacts

  • CAPEC-187 Malicious Automated Software Update