4.8
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:Y/R:U/V:D/RE:M/U:Amber
Description
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
Basic Information
ID
CVE-2026-0270
Source
palo_alto
Published
Jun 10, 2026 at 20:59
Affected Product
Vendor
Palo Alto Networks
Product
Cortex XSOAR
Version
8.13
Affected Versions
Palo Alto Networks Cortex XSOAR 8.13
Palo Alto Networks Cortex XSOAR 8.12.0
Palo Alto Networks Cortex XSOAR 8.11.0
Palo Alto Networks Cortex XSOAR 8.10.0
Palo Alto Networks Cortex XSOAR 8.12.0
Palo Alto Networks Cortex XSOAR 8.11.0
Palo Alto Networks Cortex XSOAR 8.10.0