CVE-2026-0233

Autonomous Digital Experience Manager: Improper validation of ADEM certificate

Severity
Low 2
CVSS 4.0
Exploited
Not listed
EPSS
0.002
7.2th percentile
Discovered by
Third party
Published by the vendor
Published
Apr 13, 2026
Assigned by palo_alto

Description

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Palo Alto Networks Autonomous Digital Experience Manager SASE / SSE / Secure Web cna-assigner
Vendor-reported affected versions (1)
  • Palo Alto Networks · Autonomous Digital Experience Manager

Credit

David Fischer with OBI

Vendor remediation

Version Minor Version Suggested Solution Autonomous Digital Experience Manager 5.10 on Windows 5.10.0 through 5.10.14 Upgrade to 5.10.14 or later.