CVE-2025-0134
Cortex XDR Broker VM: Authenticated Code Injection Vulnerability in Broker VM
Severity
Medium 6.5
CVSS 4.0
Exploited
Not listed
EPSS
0.005
41.5th percentile
Discovered by
Unknown
Vendor-published field
Published
May 14, 2025
Assigned by palo_alto
Description
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.
Weakness: CWE-94
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cortex XDR | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Cortex XDR Broker VM
Credit
Christiaan van Aken
Vendor remediation
This issue is fixed in Cortex XDR Broker VM 26.0.119, and all later Cortex XDR Broker VM versions. * If you enabled automatic upgrades for Broker VM, then no action is required at this time. * If you did not enable automatic upgrades, then we recommend you do so for Broker VM to ensure that you always have the latest security patches installed in your software.