CVE-2026-0304

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

  • Published Sep 10, 2026
  • CVSS 4.8 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-0304 at the National Vulnerability Database