Executive brief
A security vulnerability has been identified in Palo Alto Networks Trust Protection Foundation, a platform used for managing digital certificates and security identities. An attacker with basic user access to the local network could execute unauthorized database commands. This could lead to the theft of sensitive data, unauthorized modification of records, or a complete takeover of the management platform.
Technical details
A SQL injection vulnerability (CWE-89) exists in Palo Alto Networks Trust Protection Foundation due to improper neutralization of special elements in SQL commands. An authenticated attacker with low privileges and adjacent network access can exploit this flaw to execute arbitrary SQL queries against the backend database. Successful exploitation can result in unauthorized data retrieval, data modification, and privilege escalation to administrative levels. The vulnerability affects multiple versions including the 24.x and 25.x release branches. Patches are available in versions 25.3.3, 25.1.8, 24.3.6, 24.1.13, and subsequent releases.
Affected products
- Palo Alto Networks Trust Protection Foundation 25.3.0 < 25.3.3, 25.1.0 < 25.1.8, 24.3.0 < 24.3.6, 24.1.0 < 24.1.13
Timeline
- 2026-05-13: disclosed: Initial publication by Palo Alto Networks
- 2026-05-13: patched