Trust Protection Foundation: SQL Injection Vulnerability
Summary
| CVE | CVE-2026-0242 |
|---|---|
| State | PUBLISHED |
| Assigner | palo_alto |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-13 19:16:58 UTC |
| Updated | 2026-05-14 16:21:23 UTC |
| Description | A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an attacker to read sensitive data, modify database contents, and escalate privileges to gain full administrative control of the platform. |
Risk And Classification
Primary CVSS: v4.0 6.1 MEDIUM from [email protected]
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber
EPSS: 0.000120000 probability, percentile 0.016220000 (date 2026-05-25)
Problem Types: CWE-89 | CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6.1 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/C... |
| 4.0 | CNA | CVSS | 6.1 | MEDIUM | CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/A... |
CVSS v4.0 Breakdown
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Palo Alto Networks | Trust Protection Foundation | affected 25.3.0 25.3.3 custom | Not specified |
| CNA | Palo Alto Networks | Trust Protection Foundation | affected 25.1.0 25.1.8 custom | Not specified |
| CNA | Palo Alto Networks | Trust Protection Foundation | affected 24.3.0 24.3.6 custom | Not specified |
| CNA | Palo Alto Networks | Trust Protection Foundation | affected 24.1.0 24.1.13 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| security.paloaltonetworks.com/CVE-2026-0242 | [email protected] | security.paloaltonetworks.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-05-13T16:00:00.000Z | Initial publication. |
Solutions
CNA: Version Minor Version Suggested Solution Trust Protection Foundation 25.3 25.3.0 through 25.3.2 Upgrade to 25.3.3 or later. Trust Protection Foundation 25.1 25.1.0 through 25.1.7 Upgrade to 25.1.8 or later. Trust Protection Foundation 24.3 24.3.0 through 24.3.5 Upgrade to 24.3.6 or later. Trust Protection Foundation 24.1 24.1.0 through 24.1.12 Upgrade to 24.1.13 or later. All older versions Upgrade to a supported fixed version.
Exploits
CNA: Palo Alto Networks is not aware of any malicious exploitation of this issue.