Executive brief
Palo Alto Networks Chronosphere Chronocollector, a tool used for gathering system metrics and monitoring data, contains a security flaw that could expose sensitive information. An attacker with access to the local network could exploit this vulnerability to retrieve internal data without needing a username or password. This could lead to the exposure of system configurations or other sensitive operational details, though it does not allow the attacker to modify data or shut down the service.
Technical details
An information disclosure vulnerability exists in Palo Alto Networks Chronosphere Chronocollector versions prior to v0.116.0. The flaw is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), where the collector service fails to properly restrict access to sensitive system data. An unauthenticated attacker located on the same adjacent network can access the service to retrieve sensitive information. The vulnerability does not require user interaction or elevated privileges. The issue is resolved in version v0.116.0 and later.
Affected products
- Palo Alto Networks Chronosphere Chronocollector < v0.116.0
Timeline
- 2026-05-13: disclosed: Initial internal discovery and publication by Palo Alto Networks
- 2026-05-13: patched: Fix released in version v0.116.0