← All Advisories

Cortex XSOAR and XSIAM Microsoft Teams Integration Fails to Verify Cryptographic Signatures, Letting Unauthenticated Users Access and Modify Protected Resources

Last refreshed2026-09-28

Status: UPDATED  |  Advisory ID: CVE-2026-0234

Key Details

CVECVE-2026-0234
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-07-07
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsPalo Alto Networks Cortex XSOAR and Palo Alto Networks cortex_xsiam
Classified asCWE-347 (Improper Verification of Cryptographic Signature)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Palo Alto NetworksCortex XSOAR
Palo Alto Networkscortex_xsiam
SubsystemsGeneral OT
SectorsMultiple

What to Know

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.

What to Do

Monitor Palo Alto Networks's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-0234
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-0234
Vendor advisoryhttps://security.paloaltonetworks.com/CVE-2026-0234