{"api_version":"1","generated_at":"2026-07-23T11:39:45+00:00","cve":"CVE-2026-0241","urls":{"html":"https://cve.report/CVE-2026-0241","api":"https://cve.report/api/cve/CVE-2026-0241.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-0241","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-0241"},"summary":{"title":"Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities","description":"Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.","state":"PUBLISHED","assigner":"palo_alto","published_at":"2026-05-13 19:16:57","updated_at":"2026-07-13 13:51:11"},"problem_types":["CWE-754","CWE-754 CWE-754 Improper Check for Unusual or Exceptional Conditions"],"metrics":[{"version":"4.0","source":"psirt@paloaltonetworks.com","type":"Secondary","score":"5.1","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"USER","valueDensity":"DIFFUSE","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"5.1","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber","data":{"Automatable":"NO","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":5.1,"baseSeverity":"MEDIUM","exploitMaturity":"UNREPORTED","privilegesRequired":"NONE","providerUrgency":"AMBER","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"DIFFUSE","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"MODERATE"}},{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}}],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0241","name":"https://security.paloaltonetworks.com/CVE-2026-0241","refsource":"psirt@paloaltonetworks.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-0241","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0241","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Palo Alto Networks","product":"Trust Protection Foundation","version":"affected 25.3.0 25.3.3 custom","platforms":[]},{"source":"CNA","vendor":"Palo Alto Networks","product":"Trust Protection Foundation","version":"affected 25.1.0 25.1.8 custom","platforms":[]},{"source":"CNA","vendor":"Palo Alto Networks","product":"Trust Protection Foundation","version":"affected 24.3.0 24.3.6 custom","platforms":[]},{"source":"CNA","vendor":"Palo Alto Networks","product":"Trust Protection Foundation","version":"affected 24.1.0 24.1.13 custom","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-05-13T16:00:00.000Z","lang":"en","value":"Initial publication."}],"solutions":[{"source":"CNA","title":"","value":"Version  Minor Version  Suggested Solution\nTrust Protection Foundation 25.3  25.3.0 through 25.3.2  Upgrade to 25.3.3 or later.\nTrust Protection Foundation 25.1  25.1.0 through 25.1.7  Upgrade to 25.1.8 or later.\nTrust Protection Foundation 24.3  24.3.0 through 24.3.5  Upgrade to 24.3.6 or later.\nTrust Protection Foundation 24.1  24.1.0 through 24.1.12  Upgrade to 24.1.13 or later.","time":"","lang":"eng"}],"workarounds":[{"source":"CNA","title":"","value":"No known workarounds exist for this issue.","time":"","lang":"eng"}],"exploits":[{"source":"CNA","title":"","value":"Palo Alto Networks is not aware of any malicious exploitation of this issue.","time":"","lang":"en"}],"credits":[{"source":"CNA","value":"Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.","lang":"en"}],"nvd_cpes":[{"cve_year":"2026","cve_id":"241","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"paloaltonetworks","cpe5":"trust_protection_foundation","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"241","cve":"CVE-2026-0241","epss":"0.000090000","percentile":"0.008790000","score_date":"2026-05-25","updated_at":"2026-05-26 00:10:59"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-0241","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-05-13T19:16:03.842883Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-05-13T19:30:09.308Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Trust Protection Foundation","vendor":"Palo Alto Networks","versions":[{"changes":[{"at":"25.3.3","status":"unaffected"}],"lessThan":"25.3.3","status":"affected","version":"25.3.0","versionType":"custom"},{"changes":[{"at":"25.1.8","status":"unaffected"}],"lessThan":"25.1.8","status":"affected","version":"25.1.0","versionType":"custom"},{"changes":[{"at":"24.3.6","status":"unaffected"}],"lessThan":"24.3.6","status":"affected","version":"24.3.0","versionType":"custom"},{"changes":[{"at":"24.1.13","status":"unaffected"}],"lessThan":"24.1.13","status":"affected","version":"24.1.0","versionType":"custom"}]}],"configurations":[{"lang":"eng","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>No specific configuration is required for exposure to this vulnerability.</p>"}],"value":"No specific configuration is required for exposure to this vulnerability."}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:palo_alto_networks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionEndExcluding":"25.3.3","versionStartIncluding":"25.3.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionEndExcluding":"25.1.8","versionStartIncluding":"25.1.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionEndExcluding":"24.3.6","versionStartIncluding":"24.3.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.13","versionStartIncluding":"24.1.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"other","value":"Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue."}],"datePublic":"2026-05-13T16:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.</p>"}],"value":"Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources."}],"exploits":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Palo Alto Networks is not aware of any malicious exploitation of this issue.</p>"}],"value":"Palo Alto Networks is not aware of any malicious exploitation of this issue."}],"impacts":[{"capecId":"CAPEC-122","descriptions":[{"lang":"en","value":"CAPEC-122 Privilege Abuse"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NO","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":5.1,"baseSeverity":"MEDIUM","exploitMaturity":"UNREPORTED","privilegesRequired":"NONE","providerUrgency":"AMBER","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"DIFFUSE","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"MODERATE"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-754","description":"CWE-754 Improper Check for Unusual or Exceptional Conditions","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-13T19:01:24.094Z","orgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","shortName":"palo_alto"},"references":[{"tags":["vendor-advisory"],"url":"https://security.paloaltonetworks.com/CVE-2026-0241"}],"solutions":[{"lang":"eng","supportingMedia":[{"base64":false,"type":"text/html","value":"<table class=\"tbl\"><tr><td>Version</td><td>Minor Version</td><td>Suggested Solution</td></tr><tr><td>Trust Protection Foundation 25.3</td><td>25.3.0 through 25.3.2</td><td>Upgrade to 25.3.3 or later.</td></tr><tr><td>Trust Protection Foundation 25.1</td><td>25.1.0 through 25.1.7</td><td>Upgrade to 25.1.8 or later.</td></tr><tr><td>Trust Protection Foundation 24.3</td><td>24.3.0 through 24.3.5</td><td>Upgrade to 24.3.6 or later.</td></tr><tr><td>Trust Protection Foundation 24.1</td><td>24.1.0 through 24.1.12</td><td>Upgrade to 24.1.13 or later.</td></tr></table>"}],"value":"Version  Minor Version  Suggested Solution\nTrust Protection Foundation 25.3  25.3.0 through 25.3.2  Upgrade to 25.3.3 or later.\nTrust Protection Foundation 25.1  25.1.0 through 25.1.7  Upgrade to 25.1.8 or later.\nTrust Protection Foundation 24.3  24.3.0 through 24.3.5  Upgrade to 24.3.6 or later.\nTrust Protection Foundation 24.1  24.1.0 through 24.1.12  Upgrade to 24.1.13 or later."}],"source":{"discovery":"INTERNAL"},"timeline":[{"lang":"en","time":"2026-05-13T16:00:00.000Z","value":"Initial publication."}],"title":"Trust Protection Foundation: Multiple Authorization Bypass Vulnerabilities","workarounds":[{"lang":"eng","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>No known workarounds exist for this issue.</p>"}],"value":"No known workarounds exist for this issue."}],"x_affectedList":["Trust Protection Foundation 25.3.0","Trust Protection Foundation 25.3.1","Trust Protection Foundation 25.3.2","Trust Protection Foundation 25.1.0","Trust Protection Foundation 25.1.1","Trust Protection Foundation 25.1.2","Trust Protection Foundation 25.1.3","Trust Protection Foundation 25.1.4","Trust Protection Foundation 25.1.5","Trust Protection Foundation 25.1.6","Trust Protection Foundation 25.1.7","Trust Protection Foundation 24.3.0","Trust Protection Foundation 24.3.1","Trust Protection Foundation 24.3.2","Trust Protection Foundation 24.3.3","Trust Protection Foundation 24.3.4","Trust Protection Foundation 24.3.5","Trust Protection Foundation 24.1.0","Trust Protection Foundation 24.1.1","Trust Protection Foundation 24.1.2","Trust Protection Foundation 24.1.3","Trust Protection Foundation 24.1.4","Trust Protection Foundation 24.1.5","Trust Protection Foundation 24.1.6","Trust Protection Foundation 24.1.7","Trust Protection Foundation 24.1.8","Trust Protection Foundation 24.1.9","Trust Protection Foundation 24.1.10","Trust Protection Foundation 24.1.11","Trust Protection Foundation 24.1.12"],"x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","assignerShortName":"palo_alto","cveId":"CVE-2026-0241","datePublished":"2026-05-13T19:01:24.094Z","dateReserved":"2025-11-03T20:44:02.327Z","dateUpdated":"2026-05-13T19:30:09.308Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-13 19:16:57","lastModifiedDate":"2026-07-13 13:51:11","problem_types":["CWE-754","CWE-754 CWE-754 Improper Check for Unusual or Exceptional Conditions"],"metrics":{"cvssMetricV40":[{"source":"psirt@paloaltonetworks.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber","baseScore":5.1,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NO","Recovery":"USER","valueDensity":"DIFFUSE","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER"}}],"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-05-13T19:16:03.842883Z","id":"CVE-2026-0241","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:paloaltonetworks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionStartIncluding":"24.1.0","versionEndExcluding":"24.1.13","matchCriteriaId":"52DC45A9-9B20-4C9C-B080-95454CBF843B"},{"vulnerable":true,"criteria":"cpe:2.3:a:paloaltonetworks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionStartIncluding":"24.3.0","versionEndExcluding":"24.3.6","matchCriteriaId":"7EEE94C3-ADA5-4F01-A670-F902B48FEF65"},{"vulnerable":true,"criteria":"cpe:2.3:a:paloaltonetworks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionStartIncluding":"25.1.0","versionEndExcluding":"25.1.8","matchCriteriaId":"134B1209-C811-42B3-9F9A-D73A039B5E7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:paloaltonetworks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionStartIncluding":"25.3.0","versionEndExcluding":"25.3.3","matchCriteriaId":"AD9D632C-8323-4099-8C50-6023335414D1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"241","Ordinal":"1","Title":"Trust Protection Foundation: Multiple Authorization Bypass Vulne","CVE":"CVE-2026-0241","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"241","Ordinal":"1","NoteData":"Incorrect Authorization vulnerabilities in Trust Protection Foundation allow attackers to bypass access controls and perform unauthorized actions on restricted resources.","Type":"Description","Title":"Trust Protection Foundation: Multiple Authorization Bypass Vulne"}]}}}