Palo Alto Cortex XSOAR Flaw in Microsoft Teams Integration Lets Attackers Access Data
ID: ff34ae1a-6145-549b-8b0c-c885fc8ea8bd
STIX ID: report--ff34ae1a-6145-549b-8b0c-c885fc8ea8bd
Feed Name: GBHackers
Threat Score
Palo Alto Networks released a critical patch for CVE-2026-0234 affecting the Microsoft Teams Marketplace integration for Cortex XSOAR and XSIAM (versions 1.5.0–1.5.51). The flaw is an improper cryptographic signature validation (CWE-347) that allows unauthenticated attackers to spoof requests and read/modify protected resources; the vendor rates it high severity (Base CVSS 4.0 score 9.2) and recommends immediate upgrade to 1.5.52 or later because no temporary mitigations are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
