Junglewise Threat Intelligence

CVE-2026-0270: Palo Alto Networks Cortex XSOAR path traversal in Linux engine

CVE-2026-0270 · Severity: info · CVSS 4.8 · Published 2026-06-10

Vendors: Palo Alto Networks.

Executive brief

A security vulnerability exists in Palo Alto Networks Cortex XSOAR, a platform used by organizations to automate and manage security operations. An attacker located on the same local network could potentially intercept and modify network traffic to place malicious files on the system. If successfully exploited, this could allow an attacker to disrupt operations or gain unauthorized access to the server hosting the software.

Technical details

A path traversal vulnerability (CWE-22) exists in the Cortex XSOAR engine for Linux. The flaw allows an unauthenticated attacker on an adjacent network to perform a man-in-the-middle (MITM) attack to intercept and manipulate network response traffic. By exploiting this, the attacker can write arbitrary files to the host system. The vulnerability is related to improper handling of file paths, potentially stemming from underlying issues similar to those found in Python's tarfile module (CVE-2007-4559). Exploitation requires the attacker to be in a position to intercept traffic and for a user/system to initiate a network request that the attacker can spoof. Palo Alto Networks has released version 8.13.0.11 to address this issue.

Affected products

  • Palo Alto Networks Cortex XSOAR engine 8.10, 8.11, 8.12, and 8.13 < 8.13.0.11 on Linux

Timeline

  • 2026-06-10: disclosed: Discovered internally by Palo Alto Networks security team.
  • 2026-06-10: advisory
  • 2026-06-10: patched: Fixed in Cortex XSOAR 8.13.0.11.

References