CVE-2026-0274

Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

Severity
High 8.1
CVSS 4.0
Exploited
Not listed
EPSS
0.003
20.7th percentile
Discovered by
Vendor
Published by the vendor
Published
Jun 10, 2026
Assigned by palo_alto

Description

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

Weakness: CWE-1390

Affected products

Vendor Product Category Matched by
Palo Alto Networks Cortex XSOAR SIEM & Log Management cna-assigner
Vendor-reported affected versions (2)
  • Palo Alto Networks · Cortex XSIAM CommvaultSecurityIQ Marketplace
  • Palo Alto Networks · Cortex XSOAR CommvaultSecurityIQ Marketplace

Credit

our internal security research teams

Vendor remediation

VERSION MINOR VERSION SUGGESTED SOLUTION Cortex XSIAM CommvaultSecurityIQ Marketplace 1.1 1.1.0 through 1.1.9 Upgrade to 1.2.0 or later. Cortex XSOAR CommvaultSecurityIQ Marketplace 1.1 1.1.0 through 1.1.9 Upgrade to 1.2.0 or later.