Home
Description
A certificate validation vulnerability in Palo Alto Networks Autonomous Digital Experience Manager on Windows allows an unauthenticated attacker with adjacent network access to execute arbitrary code with NT AUTHORITY\SYSTEM privileges.
Problem types
CWE-295: Improper Certificate Validation
Product status
5.10.0 (custom) before 5.10.14
Timeline
| 2026-04-08: | Initial publication. |
| 2026-04-08: | Corrected the version ranges. |
Credits
David Fischer with OBI
References
security.paloaltonetworks.com/CVE-2026-0233
