CVE-2026-0240

EUVD-2026-30092
An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.7 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 15.11%
Affected Products (NVD)
VendorProductVersion
paloaltonetworkstrust_protection_foundation
24.1.0 ≤
𝑥
< 24.1.13
paloaltonetworkstrust_protection_foundation
24.3.0 ≤
𝑥
< 24.3.6
paloaltonetworkstrust_protection_foundation
25.1.0 ≤
𝑥
< 25.1.8
paloaltonetworkstrust_protection_foundation
25.3.0 ≤
𝑥
< 25.3.3
𝑥
= Vulnerable software versions