{"api_version":"1","generated_at":"2026-07-23T14:38:15+00:00","cve":"CVE-2026-0242","urls":{"html":"https://cve.report/CVE-2026-0242","api":"https://cve.report/api/cve/CVE-2026-0242.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-0242","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-0242"},"summary":{"title":"Trust Protection Foundation: SQL Injection Vulnerability","description":"A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an attacker to read sensitive data, modify database contents, and escalate privileges to gain full administrative control of the platform.","state":"PUBLISHED","assigner":"palo_alto","published_at":"2026-05-13 19:16:58","updated_at":"2026-05-14 16:21:23"},"problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":[{"version":"4.0","source":"psirt@paloaltonetworks.com","type":"Secondary","score":"6.1","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"6.1","severity":"MEDIUM","vector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:Y/R:U/V:C/RE:M/U:Amber","data":{"Automatable":"YES","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":6.1,"baseSeverity":"MEDIUM","exploitMaturity":"UNREPORTED","privilegesRequired":"LOW","providerUrgency":"AMBER","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:Y/R:U/V:C/RE:M/U:Amber","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"MODERATE"}}],"references":[{"url":"https://security.paloaltonetworks.com/CVE-2026-0242","name":"https://security.paloaltonetworks.com/CVE-2026-0242","refsource":"psirt@paloaltonetworks.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-0242","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0242","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Palo Alto Networks","product":"Trust Protection Foundation","version":"affected 25.3.0 25.3.3 custom","platforms":[]},{"source":"CNA","vendor":"Palo Alto Networks","product":"Trust Protection Foundation","version":"affected 25.1.0 25.1.8 custom","platforms":[]},{"source":"CNA","vendor":"Palo Alto Networks","product":"Trust Protection Foundation","version":"affected 24.3.0 24.3.6 custom","platforms":[]},{"source":"CNA","vendor":"Palo Alto Networks","product":"Trust Protection Foundation","version":"affected 24.1.0 24.1.13 custom","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-05-13T16:00:00.000Z","lang":"en","value":"Initial publication."}],"solutions":[{"source":"CNA","title":"","value":"Version                             Minor Version            Suggested Solution\nTrust Protection Foundation 25.3    25.3.0 through 25.3.2    Upgrade to 25.3.3 or later.\nTrust Protection Foundation 25.1    25.1.0 through 25.1.7    Upgrade to 25.1.8 or later.\nTrust Protection Foundation 24.3    24.3.0 through 24.3.5    Upgrade to 24.3.6 or later.\nTrust Protection Foundation 24.1    24.1.0 through 24.1.12   Upgrade to 24.1.13 or later.\nAll older versions                                           Upgrade to a supported fixed version.","time":"","lang":"eng"}],"workarounds":[],"exploits":[{"source":"CNA","title":"","value":"Palo Alto Networks is not aware of any malicious exploitation of this issue.","time":"","lang":"en"}],"credits":[{"source":"CNA","value":"Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"242","cve":"CVE-2026-0242","epss":"0.000120000","percentile":"0.016220000","score_date":"2026-05-25","updated_at":"2026-05-26 00:10:59"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-0242","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-05-13T19:17:12.940083Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-05-13T19:29:39.078Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Trust Protection Foundation","vendor":"Palo Alto Networks","versions":[{"changes":[{"at":"25.3.3","status":"unaffected"}],"lessThan":"25.3.3","status":"affected","version":"25.3.0","versionType":"custom"},{"changes":[{"at":"25.1.8","status":"unaffected"}],"lessThan":"25.1.8","status":"affected","version":"25.1.0","versionType":"custom"},{"changes":[{"at":"24.3.6","status":"unaffected"}],"lessThan":"24.3.6","status":"affected","version":"24.3.0","versionType":"custom"},{"changes":[{"at":"24.1.13","status":"unaffected"}],"lessThan":"24.1.13","status":"affected","version":"24.1.0","versionType":"custom"}]}],"configurations":[{"lang":"eng","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>No special configuration is required to be affected by this vulnerability.</p>"}],"value":"No special configuration is required to be affected by this vulnerability."}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:palo_alto_networks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionEndExcluding":"25.3.3","versionStartIncluding":"25.3.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionEndExcluding":"25.1.8","versionStartIncluding":"25.1.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionEndExcluding":"24.3.6","versionStartIncluding":"24.3.0","vulnerable":true},{"criteria":"cpe:2.3:a:palo_alto_networks:trust_protection_foundation:*:*:*:*:*:*:*:*","versionEndExcluding":"24.1.13","versionStartIncluding":"24.1.0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"other","value":"Palo Alto Networks thanks our internal security research teams for discovering and reporting this issue."}],"datePublic":"2026-05-13T16:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an attacker to read sensitive data, modify database contents, and escalate privileges to gain full administrative control of the platform.</p>"}],"value":"A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an attacker to read sensitive data, modify database contents, and escalate privileges to gain full administrative control of the platform."}],"exploits":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Palo Alto Networks is not aware of any malicious exploitation of this issue.</p>"}],"value":"Palo Alto Networks is not aware of any malicious exploitation of this issue."}],"impacts":[{"capecId":"CAPEC-66","descriptions":[{"lang":"en","value":"CAPEC-66 SQL Injection"}]}],"metrics":[{"cvssV4_0":{"Automatable":"YES","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":6.1,"baseSeverity":"MEDIUM","exploitMaturity":"UNREPORTED","privilegesRequired":"LOW","providerUrgency":"AMBER","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:Y/R:U/V:C/RE:M/U:Amber","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"MODERATE"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-13T19:04:52.841Z","orgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","shortName":"palo_alto"},"references":[{"tags":["vendor-advisory"],"url":"https://security.paloaltonetworks.com/CVE-2026-0242"}],"solutions":[{"lang":"eng","supportingMedia":[{"base64":false,"type":"text/html","value":"<table class=\"tbl\"><thead><tr><th>Version</th><th>&nbsp;Minor Version</th><th>Suggested Solution</th></tr></thead><tbody><tr><td>Trust Protection Foundation 25.3</td><td>&nbsp;<span>25.3.0 through 25.3.2</span></td><td>Upgrade to 25.3.3 or later.</td></tr><tr><td>Trust Protection Foundation 25.1</td><td>&nbsp;<span>25.1.0 through 25.1.7</span></td><td>Upgrade to 25.1.8 or later.</td></tr><tr><td>Trust Protection Foundation 24.3</td><td>&nbsp;<span>24.3.0 through 24.3.5</span></td><td>Upgrade to 24.3.6 or later.</td></tr><tr><td>Trust Protection Foundation 24.1</td><td>&nbsp;<span>24.1.0 through 24.1.12</span></td><td>Upgrade to 24.1.13 or later.</td></tr><tr><td>All older versions</td><td>&nbsp;</td><td>Upgrade to a supported fixed version.</td></tr></tbody></table>"}],"value":"Version                             Minor Version            Suggested Solution\nTrust Protection Foundation 25.3    25.3.0 through 25.3.2    Upgrade to 25.3.3 or later.\nTrust Protection Foundation 25.1    25.1.0 through 25.1.7    Upgrade to 25.1.8 or later.\nTrust Protection Foundation 24.3    24.3.0 through 24.3.5    Upgrade to 24.3.6 or later.\nTrust Protection Foundation 24.1    24.1.0 through 24.1.12   Upgrade to 24.1.13 or later.\nAll older versions                                           Upgrade to a supported fixed version."}],"source":{"discovery":"INTERNAL"},"timeline":[{"lang":"en","time":"2026-05-13T16:00:00.000Z","value":"Initial publication."}],"title":"Trust Protection Foundation: SQL Injection Vulnerability","x_affectedList":["Trust Protection Foundation 25.3.0","Trust Protection Foundation 25.3.1","Trust Protection Foundation 25.3.2","Trust Protection Foundation 25.1.0","Trust Protection Foundation 25.1.1","Trust Protection Foundation 25.1.2","Trust Protection Foundation 25.1.3","Trust Protection Foundation 25.1.4","Trust Protection Foundation 25.1.5","Trust Protection Foundation 25.1.6","Trust Protection Foundation 25.1.7","Trust Protection Foundation 24.3.0","Trust Protection Foundation 24.3.1","Trust Protection Foundation 24.3.2","Trust Protection Foundation 24.3.3","Trust Protection Foundation 24.3.4","Trust Protection Foundation 24.3.5","Trust Protection Foundation 24.1.0","Trust Protection Foundation 24.1.1","Trust Protection Foundation 24.1.2","Trust Protection Foundation 24.1.3","Trust Protection Foundation 24.1.4","Trust Protection Foundation 24.1.5","Trust Protection Foundation 24.1.6","Trust Protection Foundation 24.1.7","Trust Protection Foundation 24.1.8","Trust Protection Foundation 24.1.9","Trust Protection Foundation 24.1.10","Trust Protection Foundation 24.1.11","Trust Protection Foundation 24.1.12"],"x_generator":{"engine":"Vulnogram 0.1.0-dev"}}},"cveMetadata":{"assignerOrgId":"d6c1279f-00f6-4ef7-9217-f89ffe703ec0","assignerShortName":"palo_alto","cveId":"CVE-2026-0242","datePublished":"2026-05-13T19:04:52.841Z","dateReserved":"2025-11-03T20:44:03.175Z","dateUpdated":"2026-05-13T19:29:39.078Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-13 19:16:58","lastModifiedDate":"2026-05-14 16:21:23","problem_types":["CWE-89","CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"],"metrics":{"cvssMetricV40":[{"source":"psirt@paloaltonetworks.com","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"ADJACENT","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","exploitMaturity":"UNREPORTED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"MODERATE","providerUrgency":"AMBER"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"242","Ordinal":"1","Title":"Trust Protection Foundation: SQL Injection Vulnerability","CVE":"CVE-2026-0242","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"242","Ordinal":"1","NoteData":"A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an attacker to read sensitive data, modify database contents, and escalate privileges to gain full administrative control of the platform.","Type":"Description","Title":"Trust Protection Foundation: SQL Injection Vulnerability"}]}}}