CVE-2026-0238 LOW

CVE-2026-0238: Broker VM: Improper Input Validation in Broker VM Certificate and Key Fields

Vendor Palo Alto Networks
Product Broker VM
Weakness CWE-20 · Input validation
Published May 13, 2026
Last update May 13, 2026

CVSS base score

1.1/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber

What the vulnerability does

01Description

A vulnerability in Palo Alto Networks Broker VM allows an authenticated administrator to inject arbitrary content into certain Broker VM fields.

Key dates

02Disclosure timeline

May 13, 2026 CVE published
May 13, 2026 Record updated