Loading vulnerability details…
CVSS v3.1
N/A
CVSS v4.0
7.2
EPSS
0.23%
Published
Apr 13, 2026
Modified
Apr 13, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
Weaknesses (CWE)
References (1)