Junglewise Threat Intelligence

CVE-2026-0241: Palo Alto Networks Trust Protection Foundation authorization bypass

CVE-2026-0241 · Severity: high · CVSS 7.2 · Published 2026-05-13

Technologies: Palo Alto Networks Trust Protection Foundation. Vendors: Palo Alto Networks.

Executive brief

Palo Alto Networks Trust Protection Foundation, a security component used for managing digital trust and identity, contains vulnerabilities that allow unauthorized users to bypass security controls. An attacker could exploit these flaws to perform actions on restricted resources they should not have access to. This could lead to unauthorized data access or disruption of security services within the local network environment.

Technical details

Multiple incorrect authorization vulnerabilities (CWE-754) exist in Palo Alto Networks Trust Protection Foundation. The root cause is an improper check for unusual or exceptional conditions during authorization processes. An attacker on the adjacent network can exploit these flaws without prior authentication or user interaction to bypass access controls. Successful exploitation allows the performance of unauthorized actions on restricted resources, potentially impacting the confidentiality, integrity, and availability of the system. Patches are available in versions 24.1.13, 24.3.6, 25.1.8, and 25.3.3.

Affected products

  • Palo Alto Networks Trust Protection Foundation 24.1.0 to 24.1.12, 24.3.0 to 24.3.5, 25.1.0 to 25.1.7, 25.3.0 to 25.3.2

Timeline

  • 2026-05-13: disclosed: Initial publication by Palo Alto Networks
  • 2026-05-13: advisory: Vendor advisory published

References

Related threats