CVE-2022-0027

MEDIUM

Cortex XSOAR 6.1-6.2, 6.5, < 6.6.0.2585049 - Authenticated Unauthorized Incident Data Access via Email Report Generation

Title source: llm
STIX 2.1

Description

An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables authenticated users in non-Read-Only groups to generate an email report that contains summary information about all incidents in the Cortex XSOAR instance, including incidents to which the user does not have access. This issue impacts: All versions of Cortex XSOAR 6.1; All versions of Cortex XSOAR 6.2; All versions of Cortex XSOAR 6.5; Cortex XSOAR 6.6 versions earlier than Cortex XSOAR 6.6.0 build 6.6.0.2585049.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://security.paloaltonetworks.com/CVE-2022-0027

Scores

CVSS v3 4.3
EPSS 0.0015
EPSS Percentile 35.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-285
Status published
Products (4)
paloaltonetworks/cortex_xsoar 6.1.0
paloaltonetworks/cortex_xsoar 6.2.0
paloaltonetworks/cortex_xsoar 6.5.0
paloaltonetworks/cortex_xsoar 6.6.0 - 6.6.0.2585049
Published May 11, 2022
Tracked Since Feb 18, 2026