CVE-2026-0274
Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.1EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
10 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red
Affected products
Palo Alto Networks · Cortex XSIAM CommvaultSecurityIQ MarketplacePalo Alto Networks · Cortex XSOAR CommvaultSecurityIQ MarketplaceWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →