CVE-2026-0233
Autonomous Digital Experience Manager: Improper validation of ADEM certificate
Severity
Low 2
CVSS 4.0
Exploited
Not listed
EPSS
0.002
7.3th percentile
Discovered by
Third party
Vendor-published field
Published
Apr 13, 2026
Assigned by palo_alto
Description
A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.
Weakness: CWE-295
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Autonomous Digital Experience Manager | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Autonomous Digital Experience Manager
Credit
David Fischer with OBI
Vendor remediation
Version Minor Version Suggested Solution Autonomous Digital Experience Manager 5.10 on Windows 5.10.0 through 5.10.14 Upgrade to 5.10.14 or later.