Executive brief
Palo Alto Networks Trust Protection Foundation, a security component used for managing digital identities and secrets, contains a vulnerability that allows an authorized user to access sensitive data from the server's secure vault. By exploiting this flaw, an attacker could impersonate any other user in the system and change critical configuration settings. This could lead to a total compromise of the trust environment and unauthorized access to protected resources.
Technical details
An information disclosure vulnerability (CWE-497) exists in Palo Alto Networks Trust Protection Foundation due to improper exposure of sensitive system information. An authenticated attacker with low privileges and adjacent network access can exploit this to retrieve sensitive data from the server's vault. Successful exploitation allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings. The vulnerability is addressed in versions 24.1.13, 24.3.6, 25.1.8, and 25.3.3.
Affected products
- Palo Alto Networks Trust Protection Foundation 24.1.0 to 24.1.12, 24.3.0 to 24.3.5, 25.1.0 to 25.1.7, 25.3.0 to 25.3.2
Timeline
- 2026-05-13: disclosed: Initial publication of the advisory by Palo Alto Networks.
- 2026-05-13: patched: Fixed versions released.