CVE-2026-0242 PUBLISHED

Trust Protection Foundation: SQL Injection Vulnerability

Assigner: palo_alto
Reserved: 03.11.2025 Published: 13.05.2026 Updated: 13.05.2026

A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an attacker to read sensitive data, modify database contents, and escalate privileges to gain full administrative control of the platform.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:Y/R:U/V:C/RE:M/U:Amber
CVSS Score: 6.1

Product Status

Vendor Palo Alto Networks
Product Trust Protection Foundation
Versions Default: unaffected
  • affected from 25.3.0 to 25.3.3 (excl.)
  • affected from 25.1.0 to 25.1.8 (excl.)
  • affected from 24.3.0 to 24.3.6 (excl.)
  • affected from 24.1.0 to 24.1.13 (excl.)

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Credits

  • Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue. other

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-66 SQL Injection