CVE-2026-0240

Trust Protection Foundation: Sensitive Information Disclosure Vulnerability

Severity
Medium 4.5
CVSS 4.0
Exploited
Not listed
EPSS
0.002
15.0th percentile
Discovered by
Vendor
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto

Description

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

Weakness: CWE-497

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • Palo Alto Networks · Trust Protection Foundation

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.

Vendor remediation

Version Minor Version Suggested Solution Trust Protection Foundation 25.3 25.3.0 through 25.3.2 Upgrade to 25.3.3 or later. Trust Protection Foundation 25.1 25.1.0 through 25.1.7 Upgrade to 25.1.8 or later. Trust Protection Foundation 24.3 24.3.0 through 24.3.5 Upgrade to 24.3.6 or later. Trust Protection Foundation 24.1 24.1.0 through 24.1.12 Upgrade to 24.1.13 or later.