CVE-2026-0238
Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields
Severity
Low 1.1
CVSS 4.0
Exploited
Not listed
EPSS
0.001
0.9th percentile
Discovered by
Vendor
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto
Description
A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.
Weakness: CWE-20
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (1)
- Palo Alto Networks · Broker VM
Credit
This issue was discovered during an internal penetration test.
Vendor remediation
Version Minor Version Suggested Solution Broker VM 30.0 30.0.24 or earlier Upgrade to 30.0.24 or later.