Executive brief
A security vulnerability exists in the Microsoft Teams integration for Palo Alto Networks Cortex XSOAR and XSIAM, which are platforms used by organizations to manage and automate security operations. This flaw allows an unauthorized person to bypass security checks and potentially access or modify sensitive internal resources. If exploited, an attacker could interfere with security workflows or gain access to protected data without needing a password or internal account.
Technical details
The vulnerability (CWE-347) stems from improper verification of cryptographic signatures within the Microsoft Teams Marketplace integration for Cortex XSOAR and XSIAM. An unauthenticated remote attacker can exploit this flaw to bypass authentication mechanisms and perform unauthorized actions on protected resources. The root cause is a failure to correctly validate the authenticity of incoming requests or tokens from the Teams integration. While some CVSS 4.0 assessments suggest high complexity, the NVD CVSS 3.1 score of 9.1 reflects a critical impact on confidentiality and integrity. Users are advised to upgrade the Microsoft Teams Marketplace integration to version 1.5.52 or later.
Affected products
- Palo Alto Networks Cortex XSOAR Microsoft Teams Marketplace integration 1.5.0 through 1.5.51
- Palo Alto Networks Cortex XSIAM Microsoft Teams Marketplace integration 1.5.0 through 1.5.51
Timeline
- 2026-04-08: disclosed: Initial publication by Palo Alto Networks
- 2026-04-08: patched: Version 1.5.52 released to address the issue
- 2026-04-13: advisory: NVD publication date