---
id: CVE-2026-0270
title: >-
  A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine
  software running on Linux  allows an unauthenticated attacker on an adjacent
  network, with the ability to intercept and manipulate network response traffic
  via a ma…
summary: >-
  A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine
  software running on Linux  allows an unauthenticated attacker on an adjacent
  network, with the ability to intercept and manipulate network response traffic
  via a ma…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: paloaltonetworks
product: cortex_xsoar
affected:
  - 'cortex_xsoar >= 8.10.0, < 8.13.0.11'
patched:
  - cortex_xsoar 8.13.0.11
published: '2026-06-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0270'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2007-4559'
    label: psirt@paloaltonetworks.com
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0270'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
epss: 0.00199
epssPercentile: 0.08612
ingestedAt: '2026-07-11T13:13:24.567Z'
---

## Overview

A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux  allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.

## Affected

- `cortex_xsoar >= 8.10.0, < 8.13.0.11`

## Remediation

Upgrade past the affected range:

- `cortex_xsoar 8.13.0.11`
