Back

MEDIUM

Cortex XDR Broker VM: Secrets Shared Across Multiple Broker VM Images

Published Aug 13, 2025

Description

A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations.

The attacker must have network access to the Broker VM to exploit this issue.

Affected products

Remediation

Vendor solution

If automatic upgrades are enabled for Broker VM, then no action is required at this time.

If automatic upgrades are not enabled for Broker VM, then we recommend that you do so to ensure that you always have the latest security patches installed in your software.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Aug 13, 2025
Updated Aug 13, 2025
Reserved Mar 10, 2025
CISA Vulnrichment
Updated Aug 13, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a