CVE-2025-0139

Autonomous Digital Experience Manager: Privilege Escalation (PE) Vulnerability

Severity
Medium 6.3
CVSS 4.0
Exploited
Not listed
EPSS
0.001
3.0th percentile
Discovered by
Unknown
Published by the vendor
Published
Jul 9, 2025
Assigned by palo_alto

Description

An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privileged user on macOS endpoints to escalate their privileges to root.

Weakness: CWE-266

Affected products

Vendor Product Category Matched by
Palo Alto Networks Autonomous Digital Experience Manager SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (1)
  • Palo Alto Networks · Autonomous Digital Experience Manager

Credit

Scott Gayou

Vendor remediation

Version Minor Version Suggested Solution Autonomous Digital Experience Manager 5.6 on macOS 5.6.0 through 5.6.6 Upgrade to 5.6.7 or later.