CVE-2026-0234

Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration

Severity
High 7.2
CVSS 4.0
Exploited
Not listed
EPSS
0.002
14.0th percentile
Discovered by
Third party
Published by the vendor
Published
Apr 13, 2026
Assigned by palo_alto

Description

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

Weakness: CWE-347

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cortex XSOAR SIEM & Log Management cna-assigner
Vendor-reported affected versions (2)
  • Palo Alto Networks · Cortex XSOAR Microsoft Teams Marketplace
  • Palo Alto Networks · Cortex XSIAM Microsoft Teams Marketplace

Credit

quinn

Vendor remediation

Version Minor Version Suggested Solution Cortex XSOAR Microsoft Teams Marketplace 1.5 1.5.0 through 1.5.51 Upgrade to 1.5.52 or later. Cortex XSIAM Microsoft Teams Marketplace 1.5 1.5.0 through 1.5.51 Upgrade to 1.5.52 or later.