Skip to content
VulniPulse
Critical9.3Vendor: HighPalo Alto Networks

Critical [CVE-2026-0274] Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

This critical-severity Palo Alto Networks advisory covers CVE-2026-0274 affecting Cortex XSOAR.

CVE-2026-0274 Published Jun 10, 2026
Affected products & platforms
Palo Alto NetworksCortex
Open vendor advisory

Android app · Google Play

Monitor future Palo Alto Networks CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

CVE-2026-0274 Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration

Affected versions
  • Cortex XSIAM CommvaultSecurityIQ Marketplace < 1.2.0
  • Cortex XSOAR CommvaultSecurityIQ Marketplace < 1.2.0

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Fixed versions
  • Cortex XSIAM CommvaultSecurityIQ Marketplace >= 1.2.0
  • Cortex XSOAR CommvaultSecurityIQ Marketplace >= 1.2.0

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • VersionMinor VersionSuggested Solution Cortex XSIAM CommvaultSecurityIQ Marketplace 1.1 1.1.0 through 1.1.9 Upgrade to 1.2.0 or later.
  • Cortex XSOAR CommvaultSecurityIQ Marketplace 1.1 1.1.0 through 1.1.9 Upgrade to 1.2.0 or later.
Workaround status
  • No known workarounds exist for this issue.

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.