CVE-2026-0274

HIGH

Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

Title source: cna
STIX 2.1

Description

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://security.paloaltonetworks.com/CVE-2026-0274

Scores

CVSS v4 8.1
EPSS 0.0032
EPSS Percentile 23.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Red

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-1390
Status published
Products (2)
Palo Alto Networks/Cortex XSIAM CommvaultSecurityIQ Marketplace 1.1.0 - 1.2.0
Palo Alto Networks/Cortex XSOAR CommvaultSecurityIQ Marketplace 1.1.0 - 1.2.0
Published Jun 10, 2026
Tracked Since Jun 11, 2026