Executive brief
A security flaw exists in the CommvaultSecurityIQ integration for Palo Alto Networks' Cortex XSOAR and XSIAM platforms, which are used for security orchestration and incident response. This vulnerability allows an unauthorized person to bypass credential checks and gain access to protected resources. An attacker could use this access to view or modify sensitive security data, potentially disrupting incident response operations.
Technical details
The vulnerability is classified as Weak Authentication (CWE-1390) resulting from improper validation of credentials within the CommvaultSecurityIQ integration. It affects versions 1.1.0 through 1.1.9 of the integration on both Cortex XSOAR and Cortex XSIAM platforms. An unauthenticated attacker can exploit this over the network without any user interaction or special privileges. Successful exploitation allows the attacker to access and modify protected resources, compromising the confidentiality, integrity, and availability of the integration's data. The issue is resolved in version 1.2.0 of the integration.
Affected products
- Palo Alto Networks Cortex XSOAR CommvaultSecurityIQ Marketplace integration 1.1.0 through 1.1.9
- Palo Alto Networks Cortex XSIAM CommvaultSecurityIQ Marketplace integration 1.1.0 through 1.1.9
Timeline
- 2026-06-10: disclosed: Initial publication by Palo Alto Networks
- 2026-06-10: patched: Fix available in version 1.2.0