ZeroHour

CVE-2026-0239

CVSS 4.0
4.9 medium
EPSS
<1%p7
Published
()
Modified
Description

An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with network access to the collector service to retrieve sensitive information.

Vendors
paloaltonetworks
Products
chronosphere collector
Weakness
CWE-497
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber

In the news

No ingested article mentions this CVE yet.