CVE-2026-0270 PUBLISHED

Cortex XSOAR: Path Traversal Vulnerability

Assigner: palo_alto
Reserved: 03.11.2025 Published: 10.06.2026 Updated: 11.06.2026

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:Y/R:U/V:D/RE:M/U:Amber
CVSS Score: 4.8

Product Status

Vendor Palo Alto Networks
Product Cortex XSOAR
Versions Default: unaffected
  • affected from 8.13 to 8.13.0.11 (excl.)
Vendor Palo Alto Networks
Product Cortex XSOAR
Versions Default: unaffected
  • Version 8.12.0 is affected
  • Version 8.11.0 is affected
  • Version 8.10.0 is affected
  • Version 6.14.0 is unaffected
  • Version 6.13.0 is unaffected
  • Version 6.12.0 is unaffected

Affected Configurations

No special configuration is required.

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Workarounds

Palo Alto Networks is not aware of any malicious exploitation of these issues.

Credits

  • Palo Alto Networks thanks the internal security team for discovering and reporting this issue. finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-88 OS Command Injection