imPC@ndo IT

Tracker / CVE-2026-0240

CVE-2026-0240

High 8.7

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

Affected products and versions

paloaltonetworks trust_protection_foundation · 24.1.0 → 24.1.13
paloaltonetworks trust_protection_foundation · 24.3.0 → 24.3.6
paloaltonetworks trust_protection_foundation · 25.1.0 → 25.1.8
paloaltonetworks trust_protection_foundation · 25.3.0 → 25.3.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References