CVE-2026-0230
Received
Received - Intake
Bypass Protection Vulnerability in Palo Alto Cortex XDR macOS Agent
Publication date: 2026-03-11
Last updated on: 2026-03-11
Assigner: Palo Alto Networks, Inc.
Description
Description
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| palo_alto_networks | cortex_xdr_agent | * |
| palo_alto_networks | cortex_xdr_agent | to 8.3.102-CE (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-754 | The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product. |