logo

Palo Alto Cortex XSOAR Flaw in Microsoft Teams Integration Lets Attackers Access Data

ID: ff34ae1a-6145-549b-8b0c-c885fc8ea8bd

STIX ID: report--ff34ae1a-6145-549b-8b0c-c885fc8ea8bd

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Divya

...
...

Palo Alto Networks released a critical patch for CVE-2026-0234 affecting the Microsoft Teams Marketplace integration for Cortex XSOAR and XSIAM (versions 1.5.0–1.5.51). The flaw is an improper cryptographic signature validation (CWE-347) that allows unauthenticated attackers to spoof requests and read/modify protected resources; the vendor rates it high severity (Base CVSS 4.0 score 9.2) and recommends immediate upgrade to 1.5.52 or later because no temporary mitigations are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.