CVE-2026-0234

Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration

Severity
High 7.2
CVSS 4.0
Exploited
Not listed
EPSS
0.002
14.2th percentile
Discovered by
Third party
Vendor-published field
Published
Apr 13, 2026
Assigned by palo_alto

Description

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

Weakness: CWE-347

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cortex XSIAM SIEM & Log Management cna-assigner
Palo Alto Networks Cortex XSOAR SIEM & Log Management cna-assigner
Vendor-reported products (2)
  • Palo Alto Networks · Cortex XSOAR Microsoft Teams Marketplace
  • Palo Alto Networks · Cortex XSIAM Microsoft Teams Marketplace

Credit

quinn

Vendor remediation

Version Minor Version Suggested Solution Cortex XSOAR Microsoft Teams Marketplace 1.5 1.5.0 through 1.5.51 Upgrade to 1.5.52 or later. Cortex XSIAM Microsoft Teams Marketplace 1.5 1.5.0 through 1.5.51 Upgrade to 1.5.52 or later.

Something wrong here?