CVE-2026-0240

HIGH

Trust Protection Foundation: Sensitive Information Disclosure Vulnerability

Title source: cna
STIX 2.1

Description

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://security.paloaltonetworks.com/CVE-2026-0240

Scores

CVSS v3 8.7
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-497
Status published
Products (5)
Palo Alto Networks/Trust Protection Foundation 24.1.0 - 24.1.13
Palo Alto Networks/Trust Protection Foundation 24.3.0 - 24.3.6
Palo Alto Networks/Trust Protection Foundation 25.1.0 - 25.1.8
Palo Alto Networks/Trust Protection Foundation 25.3.0 - 25.3.3
paloaltonetworks/trust_protection_foundation 24.1.0 - 24.1.13
Published May 13, 2026
Tracked Since May 14, 2026