CVE-2026-0242: Palo Alto Networks Trust Protection Foundation

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL commands against the product database. Successful exploitation could allow an attacker to read sensitive data, modify database contents, and escalate privileges to gain full administrative control of the platform.

Affected products

  • Palo Alto Networks Trust Protection Foundation: from 25.3.0, before 25.3.3 (fixed in 25.3.3); from 25.1.0, before 25.1.8 (fixed in 25.1.8); from 24.3.0, before 24.3.6 (fixed in 24.3.6); from 24.1.0, before 24.1.13 (fixed in 24.1.13)

Published 2026-05-13. Last modified 2026-06-17.