Junglewise Threat Intelligence

CVE-2026-0240: Palo Alto Networks Trust Protection Foundation information disclosure in vault

CVE-2026-0240 · Severity: high · CVSS 8.7 · Published 2026-05-13

Technologies: Palo Alto Networks Trust Protection Foundation. Vendors: Palo Alto Networks.

Executive brief

Palo Alto Networks Trust Protection Foundation, a security component used for managing digital identities and secrets, contains a vulnerability that allows an authorized user to access sensitive data from the server's secure vault. By exploiting this flaw, an attacker could impersonate any other user in the system and change critical configuration settings. This could lead to a total compromise of the trust environment and unauthorized access to protected resources.

Technical details

An information disclosure vulnerability (CWE-497) exists in Palo Alto Networks Trust Protection Foundation due to improper exposure of sensitive system information. An authenticated attacker with low privileges and adjacent network access can exploit this to retrieve sensitive data from the server's vault. Successful exploitation allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings. The vulnerability is addressed in versions 24.1.13, 24.3.6, 25.1.8, and 25.3.3.

Affected products

  • Palo Alto Networks Trust Protection Foundation 24.1.0 to 24.1.12, 24.3.0 to 24.3.5, 25.1.0 to 25.1.7, 25.3.0 to 25.3.2

Timeline

  • 2026-05-13: disclosed: Initial publication of the advisory by Palo Alto Networks.
  • 2026-05-13: patched: Fixed versions released.

References

Related threats