CVE-2026-0274
Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration
Severity
High 8.1
CVSS 4.0
Exploited
Not listed
EPSS
0.003
20.7th percentile
Discovered by
Vendor
Published by the vendor
Published
Jun 10, 2026
Assigned by palo_alto
Description
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
Weakness: CWE-1390
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cortex XSOAR | SIEM & Log Management | cna-assigner |
Vendor-reported affected versions (2)
- Palo Alto Networks · Cortex XSIAM CommvaultSecurityIQ Marketplace
- Palo Alto Networks · Cortex XSOAR CommvaultSecurityIQ Marketplace
Credit
our internal security research teams
Vendor remediation
VERSION MINOR VERSION SUGGESTED SOLUTION Cortex XSIAM CommvaultSecurityIQ Marketplace 1.1 1.1.0 through 1.1.9 Upgrade to 1.2.0 or later. Cortex XSOAR CommvaultSecurityIQ Marketplace 1.1 1.1.0 through 1.1.9 Upgrade to 1.2.0 or later.