CVE Database
/

CVE-2026-0240

Back to search

CVE-2026-0240

Published: May 13, 2026

Modified: May 15, 2026

PUBLISHED

Description

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

VendorProductVersions

Palo Alto Networks

Trust Protection Foundation

affected
25.3.0 - < 25.3.3
affected
25.1.0 - < 25.1.8
affected
24.3.0 - < 24.3.6
affected
24.1.0 - < 24.1.13

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now