CVE-2026-0230
Cortex XDR Agent: Local Administrator can disable the agent on macOS
Severity
Medium 4
CVSS 4.0
Exploited
Not listed
EPSS
0.001
4.1th percentile
Discovered by
Third party
Published by the vendor
Published
Mar 11, 2026
Assigned by palo_alto
Description
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.
Weakness: CWE-754
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cortex XDR | Endpoint / EDR | cna-assigner |
Vendor-reported affected versions (1)
- Palo Alto Networks · Cortex XDR Agent
Credit
Michael Roitzsch, Barkhausen Institut gGmbH Carsten Weinhold, Barkhausen Institut gGmbH
Vendor remediation
This issue is fixed in Cortex XDR Agent 8.9.0, Cortex XDR Agent 8.7.101-CE, Cortex XDR Agent 8.3.102-CE, and all later Cortex XDR Agent versions.