CVE-2026-0230

Cortex XDR Agent: Local Administrator can disable the agent on macOS

Severity
Medium 4
CVSS 4.0
Exploited
Not listed
EPSS
0.001
4.1th percentile
Discovered by
Third party
Published by the vendor
Published
Mar 11, 2026
Assigned by palo_alto

Description

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.

Weakness: CWE-754

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cortex XDR Endpoint / EDR cna-assigner
Vendor-reported affected versions (1)
  • Palo Alto Networks · Cortex XDR Agent

Credit

Michael Roitzsch, Barkhausen Institut gGmbH Carsten Weinhold, Barkhausen Institut gGmbH

Vendor remediation

This issue is fixed in Cortex XDR Agent 8.9.0, Cortex XDR Agent 8.7.101-CE, Cortex XDR Agent 8.3.102-CE, and all later Cortex XDR Agent versions.