Local Privilege Escalation Vulnerability in Palo Alto Networks Cortex XDR Agent on Windows
CVE-2026-0232

4MEDIUM

Key Information:

Vendor
CVE Published:
13 April 2026

Badges

👾 Exploit Exists

What is CVE-2026-0232?

A security flaw exists in the Palo Alto Networks Cortex XDR Agent on Windows, enabling local Windows administrators to turn off the agent. This vulnerability could be exploited by malicious actors to evade detection, presenting significant risks to system integrity and security.

Affected Version(s)

Cortex XDR Agent Windows 9.0 < 9.0.1

Cortex XDR Agent Windows 8.9 < 8.9.1

Cortex XDR Agent Windows 8.7-CE < 8.7.101-CE

References

CVSS V4

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

WhatThe0xDoin
.