CVE-2026-0238
Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields
Severity
Low 1.1
CVSS 4.0
Exploited
Not listed
EPSS
0.001
0.9th percentile
Discovered by
Vendor
Vendor-published field
Published
May 13, 2026
Assigned by palo_alto
Description
A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.
Weakness: CWE-20
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Broker VM | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Broker VM
Credit
This issue was discovered during an internal penetration test.
Vendor remediation
Version Minor Version Suggested Solution Broker VM 30.0 30.0.24 or earlier Upgrade to 30.0.24 or later.