An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2026-0234 |
|
History
Mon, 13 Apr 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources. | |
| Title | Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration | |
| First Time appeared |
Palo Alto Networks
Palo Alto Networks cortex Xsiam Microsoft Teams Marketplace Palo Alto Networks cortex Xsoar Microsoft Teams Marketplace |
|
| Weaknesses | CWE-347 | |
| CPEs | cpe:2.3:a:palo_alto_networks:cortex_xsiam_microsoft_teams_marketplace:*:*:*:*:*:*:*:* cpe:2.3:a:palo_alto_networks:cortex_xsoar_microsoft_teams_marketplace:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Palo Alto Networks
Palo Alto Networks cortex Xsiam Microsoft Teams Marketplace Palo Alto Networks cortex Xsoar Microsoft Teams Marketplace |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2026-04-13T07:15:03.667Z
Reserved: 2025-11-03T20:43:55.337Z
Link: CVE-2026-0234
No data.
Status : Received
Published: 2026-04-13T08:16:22.367
Modified: 2026-04-13T08:16:22.367
Link: CVE-2026-0234
No data.
OpenCVE Enrichment
Updated: 2026-04-13T12:36:49Z