« Volver al listado

CVE-2026-0230

Estado: Pendiente de análisisMedia (4)—

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-0230",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-0230",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-11T20:18:26.611672Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "psirt@paloaltonetworks.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "USER",
          "baseScore": 4,
          "Automatable": "YES",
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "valueDensity": "DIFFUSE",
          "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Amber",
          "exploitMaturity": "UNREPORTED",
          "providerUrgency": "AMBER",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "HIGH",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "MODERATE",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@paloaltonetworks.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:palo_alto_networks:cortex_xdr_agent:8.7-CE:*:*:*:*:macOS:*:*",
            "cpe:2.3:a:palo_alto_networks:cortex_xdr_agent:8.3-CE:*:*:*:*:macOS:*:*",
            "cpe:2.3:a:palo_alto_networks:cortex_xdr_agent:8.3.101-CE:*:*:*:*:macOS:*:*"
          ],
          "vendor": "Palo Alto Networks",
          "product": "Cortex XDR Agent",
          "versions": [
            {
              "status": "unaffected",
              "version": "9.1.0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "9.0.0",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "8.9.0",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "8.7.101-CE",
                  "status": "unaffected"
                }
              ],
              "version": "8.7-CE",
              "lessThan": "8.7.101-CE",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "8.3.102-CE",
                  "status": "unaffected"
                }
              ],
              "version": "8.3-CE",
              "lessThan": "8.3.102-CE",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "macOS"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-11T18:16:21.170",
  "references": [
    {
      "url": "https://security.paloaltonetworks.com/CVE-2026-0230",
      "source": "psirt@paloaltonetworks.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@paloaltonetworks.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-754"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection."
    },
    {
      "lang": "es",
      "value": "Un problema con un mecanismo de protección en el agente Cortex XDR de Palo Alto Networks en macOS permite a un administrador local deshabilitar el agente. Este problema podría ser aprovechado por malware para realizar actividad maliciosa sin detección."
    }
  ],
  "lastModified": "2026-06-17T10:10:34.360",
  "sourceIdentifier": "psirt@paloaltonetworks.com"
}