---
id: CVE-2026-0240
title: >-
  An information disclosure vulnerability in Trust Protection Foundation enables
  an authenticated attacker to obtain sensitive information from the server's
  vault
summary: >-
  An information disclosure vulnerability in Trust Protection Foundation enables
  an authenticated attacker to obtain sensitive information from the server's
  vault. Successful exploitation of this issue allows the attacker to
  impersonate an…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'
cwe:
  - CWE-497
vendor: paloaltonetworks
product: trust_protection_foundation
affected:
  - 'trust_protection_foundation >= 24.1.0, < 24.1.13'
  - 'trust_protection_foundation >= 24.3.0, < 24.3.6'
  - 'trust_protection_foundation >= 25.1.0, < 25.1.8'
  - 'trust_protection_foundation >= 25.3.0, < 25.3.3'
patched:
  - trust_protection_foundation 25.3.3
published: '2026-05-13'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0240'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0240'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
epss: 0.00239
epssPercentile: 0.15306
ingestedAt: '2026-07-13T14:27:26.696Z'
---

## Overview

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

## Affected

- `trust_protection_foundation >= 24.1.0, < 24.1.13`
- `trust_protection_foundation >= 24.3.0, < 24.3.6`
- `trust_protection_foundation >= 25.1.0, < 25.1.8`
- `trust_protection_foundation >= 25.3.0, < 25.3.3`

## Remediation

Upgrade past the affected range:

- `trust_protection_foundation 25.3.3`
