CVE-2026-0238

Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields

Severity
Low 1.1
CVSS 4.0
Exploited
Not listed
EPSS
0.001
0.9th percentile
Discovered by
Vendor
Vendor-published field
Published
May 13, 2026
Assigned by palo_alto

Description

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

Weakness: CWE-20

Affected products

Vendor Product Category Matched by
Palo Alto Networks Broker VM SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · Broker VM

Credit

This issue was discovered during an internal penetration test.

Vendor remediation

Version Minor Version Suggested Solution Broker VM 30.0 30.0.24 or earlier Upgrade to 30.0.24 or later.

Something wrong here?