---
id: CVE-2026-0234
title: >-
  An improper verification of cryptographic signature vulnerability exists in
  Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams
  that enables an unauthenticated user to access and modify protected resources.
summary: >-
  An improper verification of cryptographic signature vulnerability exists in
  Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams
  that enables an unauthenticated user to access and modify protected resources.
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-347
vendor: paloaltonetworks
product: cortex_xsiam
affected:
  - 'cortex_xsiam >= 1.5.0, < 1.5.52'
  - 'cortex_xsoar >= 1.5.0, < 1.5.52'
patched:
  - cortex_xsiam 1.5.52
  - cortex_xsoar 1.5.52
published: '2026-04-13'
updated: '2026-07-07'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0234'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0234'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
epss: 0.00231
epssPercentile: 0.12435
ingestedAt: '2026-07-07T18:42:24.221Z'
---

## Overview

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

## Affected

- `cortex_xsiam >= 1.5.0, < 1.5.52`
- `cortex_xsoar >= 1.5.0, < 1.5.52`

## Remediation

Upgrade past the affected range:

- `cortex_xsiam 1.5.52`
- `cortex_xsoar 1.5.52`
