CVE-2026-0242

Trust Protection Foundation: SQL Injection Vulnerability

Severity
Medium 6.1
CVSS 4.0
Exploited
Not listed
EPSS
0.002
16.4th percentile
Discovered by
Vendor
Vendor-published field
Published
May 13, 2026
Assigned by palo_alto

Description

A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an attacker to read sensitive data, modify database contents, and escalate privileges to gain full administrative control of the platform.

Weakness: CWE-89

Affected products

Vendor Product Category Matched by
Palo Alto Networks Venafi Trust Protection Platform Identity / IAM / MFA cna-assigner
Vendor-reported products (1)
  • Palo Alto Networks · Trust Protection Foundation

Credit

Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.

Vendor remediation

Version Minor Version Suggested Solution Trust Protection Foundation 25.3 25.3.0 through 25.3.2 Upgrade to 25.3.3 or later. Trust Protection Foundation 25.1 25.1.0 through 25.1.7 Upgrade to 25.1.8 or later. Trust Protection Foundation 24.3 24.3.0 through 24.3.5 Upgrade to 24.3.6 or later. Trust Protection Foundation 24.1 24.1.0 through 24.1.12 Upgrade to 24.1.13 or later. All older versions Upgrade to a supported fixed version.

Something wrong here?