CVE-2026-0232
MEDIUMCortex XDR Agent: Local Administrator can disable the agent on Windows
Title source: cnaDescription
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
Scores
CVSS v4
4.0
EPSS
0.0002
EPSS Percentile
4.3%
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/AU:Y/R:U/V:D/RE:M/U:Amber
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-15
Status
published
Products (9)
Palo Alto Networks/Cortex XDR Agent
7.9-CE - 7.9-CE-CU-2120
Palo Alto Networks/Cortex XDR Agent
8.3-CE - 8.3-CE-CU-2120
Palo Alto Networks/Cortex XDR Agent
8.7-CE
Palo Alto Networks/Cortex XDR Agent
8.7-CE - 8.7.101-CE
Palo Alto Networks/Cortex XDR Agent
8.9
Palo Alto Networks/Cortex XDR Agent
8.9 - 8.9.1
Palo Alto Networks/Cortex XDR Agent
9.0
Palo Alto Networks/Cortex XDR Agent
9.0 - 9.0.1
Palo Alto Networks/Cortex XDR Agent
9.1.0 - 5.10.14
Published
Apr 13, 2026
Tracked Since
Apr 13, 2026