Palo Alto Networks Trust Protection Foundation SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability exists in Trust Protection Foundation, allowing authenticated attackers to execute arbitrary SQL commands on the product database. This exploitation could lead to unauthorized access to sensitive data, modification of database contents, and privilege escalation, potentially granting full administrative control of the platform. The vulnerability affects Trust Protection Foundation versions 25.3.0 prior to 25.3.3, 25.1.0 prior to 25.1.8, 24.3.0 prior to 24.3.6, and 24.1.0 prior to 24.1.13.

Impact

Exploitation of this vulnerability could result in unauthorized database access, data manipulation, and elevated privileges, allowing an attacker to gain full administrative rights on the platform.

Remediation

Users can upgrade to Trust Protection Foundation version 25.3.3 or later, 25.1.8 or later, 24.3.6 or later, or 24.1.13 or later, depending on their current version. Those on older versions should upgrade to a supported fixed version.

Added: May 13, 2026, 7:42 PM
Updated: May 13, 2026, 7:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
5.2
remediation
0.0
relevance
8.2
threat
0.0
urgency
5.7
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.