VendorsPalo Alto Networkscortex_xsoarall versions
Vulnerabilities

Palo Alto Networks Cortex Xsoar

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-3044
Cortex XSOAR: Unauthorized Usage of the REST API
Published 2021-06-22 · Modified
9.8EPSS 0.014
CVE-2026-0234
Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration
Published 2026-04-13 · Undergoing Analysis
9.1EPSS 0.002
CVE-2021-3051
Cortex XSOAR: Authentication Bypass in SAML Authentication
Published 2021-09-08 · Modified
8.1EPSS 0.006
CVE-2026-0270
Cortex XSOAR: Path Traversal Vulnerability
Published 2026-06-10 · Analyzed
7.5EPSS 0.002
CVE-2022-0020
Cortex XSOAR: Stored Cross-Site Scripting (XSS) Vulnerability in Web Interface
Published 2022-02-10 · Modified
6.81 PoCEPSS 0.017
CVE-2023-3282
Cortex XSOAR: Local Privilege Escalation (PE) Vulnerability in Cortex XSOAR Engine
Published 2023-11-08 · Modified
6.7EPSS 0.002
CVE-2022-0031
Cortex XSOAR: Local Privilege Escalation (PE) Vulnerability in Cortex XSOAR Engine
Published 2022-11-09 · Modified
6.7EPSS 0.001
CVE-2023-0003
Cortex XSOAR: Local File Disclosure Vulnerability in the Cortex XSOAR Server
Published 2023-02-08 · Modified
6.5EPSS 0.013
CVE-2021-3034
Cortex XSOAR: Secrets for SAML single sign-on (SSO) integration may be logged in system logs
Published 2021-03-10 · Modified
5.1EPSS 0.002
CVE-2022-0027
Cortex XSOAR: Incorrect Authorization Vulnerability When Generating Reports
Published 2022-05-11 · Modified
4.3EPSS 0.005
CVE-2021-3049
Cortex XSOAR: Improper Authorization of Incident Investigations Vulnerability
Published 2021-09-08 · Modified
4.3EPSS 0.005