CVE-2026-0238

Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields

Severity
Low 1.1
CVSS 4.0
Exploited
Not listed
EPSS
0.001
0.9th percentile
Discovered by
Vendor
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto

Description

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • Palo Alto Networks · Broker VM

Credit

This issue was discovered during an internal penetration test.

Vendor remediation

Version Minor Version Suggested Solution Broker VM 30.0 30.0.24 or earlier Upgrade to 30.0.24 or later.