---
id: CVE-2026-0274
title: >-
  An improper validation of credentials vulnerability in the CommvaultSecurityIQ
  integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated
  attacker to access and modify protected resources.
summary: >-
  An improper validation of credentials vulnerability in the CommvaultSecurityIQ
  integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated
  attacker to access and modify protected resources.
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-1390
vendor: paloaltonetworks
product: cortex_xsiam_commvaultsecurityiq_marketplace
affected:
  - cortex_xsiam_commvaultsecurityiq_marketplace = 1.1.0
  - cortex_xsoar_commvaultsecurityiq_marketplace = 1.1.0
published: '2026-06-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-0274'
references:
  - url: 'https://security.paloaltonetworks.com/CVE-2026-0274'
    label: psirt@paloaltonetworks.com
tags:
  - nvd
epss: 0.00285
epssPercentile: 0.21279
ingestedAt: '2026-07-11T13:13:24.642Z'
---

## Overview

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

## Affected

- `cortex_xsiam_commvaultsecurityiq_marketplace = 1.1.0`
- `cortex_xsoar_commvaultsecurityiq_marketplace = 1.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
