CVE-2026-0240

HIGH

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this iss...

Affects 0 products across 2 vendors.

BCS3.01
CVSS 3.18.7
CVSS v44.5
EPSS0.2%
Percentile15th
PatchUnknown
CVSS Vector — Plain English Exploitable from adjacent network, low complexity, low privileges required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, no availability impact.
CWE Weakness Definitions
CWE-497: CWE-497
Related Attack Patterns (CAPEC)
CAPEC-170 Web Application Fingerprinting
via CWE-497
CAPEC-694 System Location Discovery
via CWE-497

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A low severity vulnerability affects Foundation systems (CVE-2026-0240). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.

BSID: BS-2026-GLOBAL-269592-I • Model: rule-based-v1 • Confidence: LOW

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-0240?
A low severity vulnerability affects Foundation systems (CVE-2026-0240). No public exploit code is currently available. Review vendor advisories and apply patches during the next maintenance window.
What is the CVSS score for CVE-2026-0240?
CVE-2026-0240 has CVSS 8.7 (High). Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N. EPSS: 0.2%.
Is CVE-2026-0240 actively exploited?
No confirmed active exploitation of CVE-2026-0240 as of 2026-07-14.
How do I remediate CVE-2026-0240?
Priority: MONITOR. PSIRT: [email protected]
What systems are affected by CVE-2026-0240?
CVE-2026-0240 affects: Foundation, Palo Alto.
Vulnerability Details
CVE IDCVE-2026-0240
BSIDBS-2026-GLOBAL-269592-I BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Published2026-05-13
Last Modified2026-07-13
ICS Relevance0%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings. CVSS vector: Not available.

Exploitation Likelihood: MINIMAL

Affected Products
VendorProductFixed Version
Foundation —
Palo Alto —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 73 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceLOW
Enriched At2026-05-24
SHA-512 Audit Hashd1a6434ef82192718f539f2623d7b6f229a26dbf27c93298d897e31ffd9749b9c15b4abf1f55d0228fcfa06482121aa5a9222603a2adb446c9ec7e3ca2d1e7d1
Related CVEs affecting Foundation
CVE-2022-50993 9.8 Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthent... CVE-2017-20216 9.8 FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple una... CVE-2025-53499 9.1 Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Abuse... CVE-2025-53495 9.1 Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Abuse... CVE-2024-25738 9.1 A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig ...
View all Foundation CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →