Executive brief
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM allows an authenticated user with network-adjacent access to execute arbitrary code with root privileges. The Broker VM is a critical component of Cortex XDR, Palo Alto's enterprise threat defense platform. Successful exploitation could lead to complete compromise of the Broker VM and the security data it manages.
Technical details
This vulnerability is an argument injection flaw (CWE-88) in the Cortex XDR Broker VM that allows privilege escalation from a low-privileged authenticated user to root. The attack requires man-in-the-middle (MitM) access on the network (adjacent attack vector) and is triggered during cloud-delivered mount actions. An attacker must be authenticated and able to intercept traffic to inject malicious arguments into commands executed by the Broker VM, achieving code execution with root privileges. The vulnerability affects Cortex XDR Broker VM versions 32.0.0 through 32.0.51 and is fixed in version 32.0.52 and later. Palo Alto Networks is unaware of active exploitation in the wild.
Affected products
- Palo Alto Networks Cortex XDR Broker VM 20.0.96 through 32.0.51
Timeline
- 2026-09-09: disclosed