Back

MEDIUM

Trust Protection Foundation: Sensitive Information Disclosure Vulnerability

Published May 13, 2026

Description

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

Affected products

Remediation

Vendor solution

Version Minor Version Suggested Solution Trust Protection Foundation 25.3 25.3.0 through 25.3.2 Upgrade to 25.3.3 or later. Trust Protection Foundation 25.1 25.1.0 through 25.1.7 Upgrade to 25.1.8 or later. Trust Protection Foundation 24.3 24.3.0 through 24.3.5 Upgrade to 24.3.6 or later. Trust Protection Foundation 24.1 24.1.0 through 24.1.12 Upgrade to 24.1.13 or later.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published May 13, 2026
Updated May 15, 2026
Reserved Nov 3, 2025
CISA Vulnrichment
Updated May 15, 2026
NVD
Status Analyzed
Modified Jul 13, 2026
Red Hat
Severity n/a
Public date n/a