Back to search
CVE-2026-0240
Published: May 13, 2026
Modified: May 15, 2026
PUBLISHED
Description
An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.
| Vendor | Product | Versions |
|---|---|---|
Palo Alto Networks | Trust Protection Foundation | affected 25.3.0 - < 25.3.3affected 25.1.0 - < 25.1.8affected 24.3.0 - < 24.3.6affected 24.1.0 - < 24.1.13 |
Weaknesses (CWE)
References
https://security.paloaltonetworks.com/CVE-2026-0240
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now