Palo Alto Networks · Cortex Xsoar · CVE-2026-0234
Name of the Vulnerable Software and Affected Versions
Palo Alto Cortex XSOAR and Cortex XSIAM versions prior to 1.5.52
Description
A flaw in the Microsoft Teams integration for Cortex XSOAR and Cortex XSIAM allows attackers to access and modify sensitive data without authentication. The integration improperly inspects digital passports, enabling attackers to forge signatures and bypass security checks. This does not require a valid username, password, or network privileges.
Recommendations
Update to version 1.5.52 or later.