---
id: CVE-2026-0239
title: >-
  An information disclosure vulnerability in the Chronosphere Chronocollector
  enables an unauthenticated attacker with network access to the collector
  service to retrieve sensitive information.
summary: >-
  An information disclosure vulnerability in the Chronosphere Chronocollector
  enables an unauthenticated attacker with network access to the collector
  service to retrieve sensitive information.
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-497
vendor: paloaltonetworks
product: chronosphere_collector
affected:
  - chronosphere_collector < 0.116.0
patched:
  - chronosphere_collector 0.116.0
published: '2026-05-13'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0239'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0239'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
epss: 0.00173
epssPercentile: 0.07061
ingestedAt: '2026-07-13T15:27:34.056Z'
---

## Overview

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

## Affected

- `chronosphere_collector < 0.116.0`

## Remediation

Upgrade past the affected range:

- `chronosphere_collector 0.116.0`
