← Vulnerability feed

Vulnerability record · CVE-2021-3044 · published 22 June 2021

CVE-2021-3044: Paloaltonetworks cortex xsoar improper authorization vulnerability

Paloaltonetworks · Cortex Xsoar

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex XSOAR 6.2.0 builds earlier than 1271065. This issue does not impact Cortex XSOAR 5.5.0, Cortex XSOAR 6.0.0, Cortex XSOAR 6.0.1, or Cortex XSOAR 6.0.2 versions. All Cortex XSOAR instances hosted by Palo Alto Networks are upgraded to resolve this vulnerability. No additional action is required for these instances.

9.8 CVSS 3.1 Critical EPSS 1.4% · top 28.5% CWE-285 · Improper authorization
9.8CVSS 3.1 base score, v2 7.5
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An improper authorization vulnerability in Palo Alto Networks Cortex XSOAR enables a remote unauthenticated attacker with network access to the Cortex XSOAR server to perform unauthorized actions through the REST API. This issue impacts: Cortex XSOAR 6.1.0 builds later than 1016923 and earlier than 1271064; Cortex XSOAR 6.2.0 builds earlier than 1271065. This issue does not impact Cortex XSOAR 5.5.0, Cortex XSOAR 6.0.0, Cortex XSOAR 6.0.1, or Cortex XSOAR 6.0.2 versions. All Cortex XSOAR instances hosted by Palo Alto Networks are upgraded to resolve this vulnerability. No additional action is required for these instances.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-3044 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2021-3051Paloaltonetworks cortex xsoar improper verification of cryptographic signature vulnerabilityAn improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-…EPSS 0.58%7.2CVE-2026-0234Paloaltonetworks cortex xsiam improper verification of cryptographic signature vulnerabilityAn improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft T…EPSS 0.23%6.7CVE-2023-3282Paloaltonetworks cortex xsoar incorrect permission assignment vulnerabilityA local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system enables a …EPSS 0.17%6.7CVE-2022-0031Paloaltonetworks cortex xsoar insufficient verification of data authenticity vulnerabilityA local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a l…EPSS 0.12%6.5CVE-2023-0003Paloaltonetworks cortex xsoar vulnerabilityA file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface…EPSS 1.3%5.4CVE-2022-0020Paloaltonetworks cortex xsoar cross-site scripting vulnerabilityA stored cross-site scripting (XSS) vulnerability in Palo Alto Network Cortex XSOAR web interface enables an authenticated network-based attacker to …EPSS 1.7%5.1CVE-2021-3034Paloaltonetworks cortex xsoar sensitive information in log file vulnerabilityAn information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO)…EPSS 0.17%4.8CVE-2026-0270Paloaltonetworks cortex xsoar path traversal vulnerabilityA path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent …EPSS 0.20%

Source: NIST National Vulnerability Database (record CVE-2021-3044), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.