Executive brief
A security vulnerability in the Palo Alto Networks Cortex XDR Broker VM allows a user who already has local access to the system to gain full administrative (root) control. The Broker VM is a component used to bridge communication between security agents and the management console. If exploited, an attacker could bypass security controls, access sensitive configuration data, or disrupt the monitoring of the corporate network.
Technical details
An improper privilege management vulnerability (CWE-269) exists in the Palo Alto Networks Cortex XDR Broker VM. The flaw allows a locally authenticated user with low privileges to execute commands or perform actions with root-level permissions. The vulnerability is present in versions starting from 20.0.96 and is fixed in version 31.0.58. Exploitation requires local access to the VM but does not require high complexity or user interaction. Successful exploitation results in a complete compromise of the Broker VM's integrity and confidentiality.
Affected products
- Palo Alto Networks Cortex XDR Broker VM 20.0.96 to 31.0.58
Timeline
- 2026-07-08: disclosed: Initial discovery and publication by Palo Alto Networks.
- 2026-07-08: patched: Fixed in version 31.0.58.
- 2026-07-09: advisory: NVD record published.