CVE-2026-0304
Cortex XDR Broker VM: Privilege Escalation Vulnerability
Severity
Medium 4.8
CVSS 4.0
Exploited
Not listed
EPSS
0.002
12.5th percentile
Discovered by
Vendor
Vendor-published field
Published
Sep 10, 2026
Assigned by palo_alto
Description
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
Weakness: CWE-88
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cortex XDR | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Cortex XDR Broker VM
Credit
internal security research teams
Vendor remediation
This issue is fixed in Cortex XDR Broker VM 32.0.52, and all later Cortex XDR Broker VM versions. * If automatic upgrades are enabled for Broker VM, then no action is required at this time. * If automatic upgrades are not enabled for Broker VM, then we recommend that you do so to ensure that you always have the latest security patches installed in your software