Skip to main content
Mallory
High

Improper Validation of Credentials in CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM

IdentifiersCVE-2026-0274CWE-1390· Weak Authentication

CVE-2026-0274 is an improper validation of credentials vulnerability in the CommvaultSecurityIQ Marketplace integration used with Cortex XSOAR and Cortex XSIAM. The issue affects CommvaultSecurityIQ integration versions prior to 1.2.0. According to the advisory, the integration improperly validates credentials, which allows requests from an unauthenticated attacker to be accepted and processed as authorized. Successful exploitation enables access to and modification of protected resources. The provided information does not identify the specific vulnerable function or code path.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated remote attacker to access and modify protected resources exposed through the vulnerable integration. This can result in unauthorized disclosure of sensitive information, unauthorized changes to data or configuration, and potential service impact. The supplied CVSS v4.0 metadata indicates network-based exploitation with low attack complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability.

Mitigation

If you can’t patch tonight, do this now.

No known workarounds exist for this issue. If immediate upgrade is not possible, exposure should be reduced by restricting network access to the affected Cortex XSOAR/XSIAM integration endpoints and limiting access to trusted administrative networks only, but the vendor states there are no known mitigations that fully address the flaw short of upgrading.

Remediation

Patch, then assume compromise.

Upgrade the CommvaultSecurityIQ Marketplace integration for Cortex XSOAR and Cortex XSIAM to version 1.2.0 or later. Affected versions are those prior to 1.2.0.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Palo Alto NetworksCommvaultsecurityiqapplication
Palo Alto NetworksCortex Xsiam Commvaultsecurityiq Marketplaceapplication
Palo Alto NetworksCortex Xsoar Commvaultsecurityiq Marketplaceapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity3

Community discussion across Reddit, Mastodon, and other social sources.