CVE-2025-0139
Autonomous Digital Experience Manager: Privilege Escalation (PE) Vulnerability
Severity
Medium 6.3
CVSS 4.0
Exploited
Not listed
EPSS
0.001
3.0th percentile
Discovered by
Unknown
Published by the vendor
Published
Jul 9, 2025
Assigned by palo_alto
Description
An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a locally authenticated low privileged user on macOS endpoints to escalate their privileges to root.
Weakness: CWE-266
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Autonomous Digital Experience Manager | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (1)
- Palo Alto Networks · Autonomous Digital Experience Manager
Credit
Scott Gayou
Vendor remediation
Version Minor Version Suggested Solution Autonomous Digital Experience Manager 5.6 on macOS 5.6.0 through 5.6.6 Upgrade to 5.6.7 or later.