---
id: CVE-2026-0233
title: >-
  A certificate validation vulnerability in Palo Alto Networks Autonomous
  Digital Experience Manager on Windows allows an unauthenticated attacker with
  adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM 
  privileges.
summary: >-
  A certificate validation vulnerability in Palo Alto Networks Autonomous
  Digital Experience Manager on Windows allows an unauthenticated attacker with
  adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM 
  privileges.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-295
vendor: paloaltonetworks
product: autonomous_digital_experience_manager
affected:
  - 'autonomous_digital_experience_manager >= 5.10.0, < 5.10.14'
patched:
  - autonomous_digital_experience_manager 5.10.14
published: '2026-04-13'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0233'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0233'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
epss: 0.00175
epssPercentile: 0.07266
ingestedAt: '2026-07-07T18:42:24.218Z'
---

## Overview

A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM  privileges.

## Affected

- `autonomous_digital_experience_manager >= 5.10.0, < 5.10.14`

## Remediation

Upgrade past the affected range:

- `autonomous_digital_experience_manager 5.10.14`
