// For flags

CVE-2026-0240

Trust Protection Foundation: Sensitive Information Disclosure Vulnerability

Severity Score

4.5
*CVSS v4

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

*Credits: Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
System
Vulnerable | Subsequent
Confidentiality
High
Low
Integrity
High
Low
Availability
None
None
Attack Vector
Adjacent
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
System
Vulnerable | Subsequent
Confidentiality
High
Low
Integrity
High
Low
Availability
None
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2025-11-03 CVE Reserved
  • 2026-05-13 CVE Published
  • 2026-05-14 EPSS Updated
  • 2026-05-15 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
CAPEC
  • CAPEC-37: Retrieve Embedded Sensitive Data
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Palo Alto Networks
Search vendor "Palo Alto Networks"
Trust Protection Foundation
Search vendor "Palo Alto Networks" for product "Trust Protection Foundation"
>= 25.3.0 < 25.3.3
Search vendor "Palo Alto Networks" for product "Trust Protection Foundation" and version " >= 25.3.0 < 25.3.3"
en
Affected
Palo Alto Networks
Search vendor "Palo Alto Networks"
Trust Protection Foundation
Search vendor "Palo Alto Networks" for product "Trust Protection Foundation"
>= 25.1.0 < 25.1.8
Search vendor "Palo Alto Networks" for product "Trust Protection Foundation" and version " >= 25.1.0 < 25.1.8"
en
Affected
Palo Alto Networks
Search vendor "Palo Alto Networks"
Trust Protection Foundation
Search vendor "Palo Alto Networks" for product "Trust Protection Foundation"
>= 24.3.0 < 24.3.6
Search vendor "Palo Alto Networks" for product "Trust Protection Foundation" and version " >= 24.3.0 < 24.3.6"
en
Affected
Palo Alto Networks
Search vendor "Palo Alto Networks"
Trust Protection Foundation
Search vendor "Palo Alto Networks" for product "Trust Protection Foundation"
>= 24.1.0 < 24.1.13
Search vendor "Palo Alto Networks" for product "Trust Protection Foundation" and version " >= 24.1.0 < 24.1.13"
en
Affected