An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0234 |
|
History
Mon, 13 Apr 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources. | |
| Title | Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration | |
| First Time appeared |
Palo Alto Networks
Palo Alto Networks cortex Xsiam Microsoft Teams Marketplace Palo Alto Networks cortex Xsoar Microsoft Teams Marketplace |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:palo_alto_networks:cortex_xsiam_microsoft_teams_marketplace:*:*:*:*:*:*:*:* cpe:2.3:a:palo_alto_networks:cortex_xsoar_microsoft_teams_marketplace:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Palo Alto Networks
Palo Alto Networks cortex Xsiam Microsoft Teams Marketplace Palo Alto Networks cortex Xsoar Microsoft Teams Marketplace |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2026-04-13T07:15:03.667Z
Reserved: 2025-11-03T20:43:55.337Z
Link: CVE-2026-0234
No data.
Status : Received
Published: 2026-04-13T08:16:22.367
Modified: 2026-04-13T08:16:22.367
Link: CVE-2026-0234
No data.
OpenCVE Enrichment
No data.
Weaknesses