CVE-2026-4761
Received
Received - Intake
Excessive Private Key Permissions in Panorama Suite
Publication date: 2026-03-25
Last updated on: 2026-04-01
Assigner: 30aa36b7-a224-4bc9-b7d3-abea20aa4887
Description
Description
When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group.
* Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed
* Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable
Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| codra | panorama_com | 25.00.004 |
| codra | panorama_e2 | 25.00.004 |
| codra | panorama_h2 | 25.00.004 |
| codra | panorama_collaborative_operation_&_execution | 25.00.004 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |