Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-0274

Опубликовано: 10 июн. 2026
Источник: nvd
CVSS3: 9.1
EPSS Низкий

Описание

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:paloaltonetworks:cortex_xsiam_commvaultsecurityiq_marketplace:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:paloaltonetworks:cortex_xsoar_commvaultsecurityiq_marketplace:1.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 21%
0.00285
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1390
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.1
github
около 2 месяцев назад

An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.

CVSS3: 9.1
fstec
около 2 месяцев назад

Уязвимость плагина CommvaultSecurityIQ платформ безопасности Cortex XSOAR и Cortex XSIAM, позволяющая нарушителю обойти существующие ограничения безопасности

EPSS

Процентиль: 21%
0.00285
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1390
NVD-CWE-noinfo