CVE-2025-0103: Palo Alto Networks Expedition

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.

Affected products

Published 2025-01-11. Last modified 2026-06-17.