CVE-2026-0274
Critical · CVSS 9.1Cortex XSOAR / Cortex XSIAM - CommvaultSecurityIQ Integration — Improper Validation of Credentials (Authentication Bypass)
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-1390, NVD-CWE-noinfo
Description
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
Search profile — drives PoC discovery
Symbols CommvaultSecurityIQCWE-1390Cortex XSOAR integrationCortex XSIAM integrationcredential validationunauthenticated accessprotected resources
Keywords CVE-2026-0274CommvaultSecurityIQCortex XSOARCortex XSIAMauthentication bypassimproper credential validationPalo Alto NetworksXSOAR integration exploitXSIAM integration PoCCWE-1390
Versions: <UNKNOWN>
References
Status: enriched · ingested 2026-07-10T18:00:26.000Z · profiled 2026-07-10T18:30:26.000Z