Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
SECURITY ADVISORYPALO ALTO NETWORKSVERIFIED

PUBLISHER UPDATE · CVE-2026-0304

CVE-2026-0304 release notes and known issues

Cortex XDR Broker VM: Privilege Escalation Vulnerability

Scope: Cortex XDR Broker VM. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Cortex XDR Broker VM

Affected versions

  • < 32.0.52

Fixed versions or updates

  • >= 32.0.52

Recommended action

This issue is fixed in Cortex XDR Broker VM 32.0.52, and all later Cortex XDR Broker VM versions. * If automatic upgrades are enabled for Broker VM, then no action is required at this time. * If automatic upgrades are not enabled for Broker VM, then we recommend that you do so to ensure that you always have the latest security patches installed in your software

Related vulnerabilities

BlackTree CVE Intelligence

Official publisher evidence

PALO ALTO NETWORKSVERIFIED

Cortex XDR Broker VM: Privilege Escalation Vulnerability

Checked 9 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source