Cortex XDR Broker VM: Privilege Escalation Vulnerability

Plan PatchCVSS 7.5CVE-2026-0304Sep 9, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

A privilege escalation vulnerability in Cortex XDR Broker VM allows an authenticated low-privileged user with man-in-the-middle (MitM) network access to execute code with root privileges on the Broker VM. This could allow an attacker to compromise endpoint detection and response monitoring across connected endpoints.

What this means
What could happen
An attacker with low-level user access and the ability to intercept network traffic could run commands with root privileges on the Cortex XDR Broker VM, potentially compromising endpoint detection and response capabilities across your organization.
Who's at risk
Organizations running Palo Alto Cortex XDR Broker VM (any version below 32.0.52) need to address this issue. The risk is highest for deployments where the Broker VM shares network segments with untrusted systems or where user account management is permissive.
How it could be exploited
An attacker first needs valid low-privileged user credentials on the Broker VM. Then, if the attacker can position themselves on the network to intercept traffic (or exploit network routing), they can execute a man-in-the-middle attack to escalate privileges to root level and run arbitrary commands on the Broker VM.
Prerequisites
  • Valid low-privileged user account on Cortex XDR Broker VM
  • Network position allowing man-in-the-middle (MitM) traffic interception (same network segment, compromised network device, or routing control)
Requires valid user credentialsRequires network-level MitM capabilityAffects security infrastructure (EDR/XDR)Medium CVSS (7.5)
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
Cortex XDR Broker VMBelow 32.0.5232.0.52+
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Cortex XDR Broker VM to version 32.0.52 or later
HARDENINGEnforce authentication for all management access to Broker VM and audit user accounts for unnecessary privileged access
Long-term hardening
0/1
HARDENINGIsolate Cortex XDR Broker VM to a dedicated, segmented network with strict access controls to limit unauthorized users and prevent MitM attacks
API: /api/v1/advisories/64f5eef6-691a-4049-a022-e984f0c6529e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Cortex XDR Broker VM: Privilege Escalation Vulnerability | CVSS 7.5 - OTPulse