{"id":"CVE-2026-0304","title":"A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.","summary":"A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.","severity":"medium","cvss":4.8,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/AU:N/R:U/V:D/RE:M/U:Amber","cwe":["CWE-88"],"vendor":"Palo Alto Networks","product":"Cortex XDR Broker VM","affected":["cortex_xdr_broker_vm >= 20.0.96 < 32.0.52"],"published":"2026-09-10","updated":"2026-09-11","sourceUpdated":"2026-09-11T04:17:06.707","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-0304","references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0304","label":"psirt@paloaltonetworks.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T00:00:00+00:00"},"cvssSource":"cna","ingestedAt":"2026-09-12T16:24:58.824Z","epss":0.00218,"epssPercentile":0.12517,"slug":"CVE-2026-0304","body":"## Overview\n\nA privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}