216.73.217.15

CVE-2026-0237

· Published 13/05/2026 18:16 · Modified 13/05/2026 18:17

Labels: CVE-2026-0237 2026-05-13CVE-2026-0237CWE-424[email protected]

Essential information

Published
13/05/2026 18:16
Modified
13/05/2026 18:17
Author
Creator
CVSS
7.3 HIGH (v3) 7.3 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to an internal automation bridge. This allows a locally authenticated non-admin user to leverage an exposed communication channel to send unauthorized commands to the browser, bypassing security controls.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
palo alto networks / prisma browser cpe:2.3:a:palo_alto_networks:prisma_browser:*:*:*:*:*:*:*:*

References