{"id":"CVE-2026-0241","title":"Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.","summary":"Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-754"],"vendor":"paloaltonetworks","product":"trust_protection_foundation","affected":["trust_protection_foundation >= 24.1.0, < 24.1.13","trust_protection_foundation >= 24.3.0, < 24.3.6","trust_protection_foundation >= 25.1.0, < 25.1.8","trust_protection_foundation >= 25.3.0, < 25.3.3"],"patched":["trust_protection_foundation 25.3.3"],"published":"2026-05-13","updated":"2026-07-13","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0241","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0241","label":"psirt@paloaltonetworks.com"}],"tags":["nvd"],"epss":0.00336,"epssPercentile":0.27051,"ingestedAt":"2026-07-13T14:27:26.715Z","slug":"CVE-2026-0241","body":"## Overview\n\nIncorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.\n\n## Affected\n\n- `trust_protection_foundation >= 24.1.0, < 24.1.13`\n- `trust_protection_foundation >= 24.3.0, < 24.3.6`\n- `trust_protection_foundation >= 25.1.0, < 25.1.8`\n- `trust_protection_foundation >= 25.3.0, < 25.3.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `trust_protection_foundation 25.3.3`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":39.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}