{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apalo_alto_networkscortex_xdr_broker_vm/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:palo_alto_networks:cortex_xdr_broker_vm:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cortex XDR Broker VM (\u003c 32.0.52)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","privilege-escalation","cortex-xdr"],"_cs_type":"threat","_cs_vendors":["Palo Alto Networks"],"content_html":"\u003cp\u003ePalo Alto Networks has disclosed a privilege escalation vulnerability, tracked as CVE-2026-0304, affecting the Cortex XDR Broker VM. The issue stems from improper neutralization of argument delimiters (CWE-88) in command processing, combined with path traversal (CAPEC-126). This vulnerability can be triggered when the Broker VM processes cloud-delivered mount actions. An attacker who is already authenticated as a low-privileged user and positioned to conduct a man-in-the-middle (MitM) attack can manipulate these commands to achieve root-level code execution on the appliance. The vulnerability affects versions of Cortex XDR Broker VM prior to 32.0.52. Palo Alto Networks reports no known in-the-wild exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability grants an attacker root privileges on the Cortex XDR Broker VM. This enables full control over the appliance, potentially allowing the attacker to intercept sensitive traffic, exfiltrate data, or further compromise the internal network segments where the Broker VM resides. The vulnerability affects all deployments that process cloud-delivered mount actions without specific configuration changes required to trigger the risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all Cortex XDR Broker VM instances to version 32.0.52 or later. If your organization does not have automatic upgrades enabled for the Broker VM, verify the current version on all internet-facing or high-exposure management appliances and initiate a manual update immediately. There are no known workarounds for this vulnerability.\u003c/p\u003e\n","date_modified":"2026-09-09T18:58:54Z","date_published":"2026-09-09T18:58:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cortex-xdr-broker-vm-priv-esc/","summary":"A privilege escalation vulnerability (CVE-2026-0304) in Palo Alto Networks Cortex XDR Broker VM allows an authenticated, low-privileged attacker with man-in-the-middle positioning to execute arbitrary code as root.","title":"Cortex XDR Broker VM Privilege Escalation Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-cortex-xdr-broker-vm-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:palo_alto_networks:cortex_xdr_broker_vm:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}