Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
- Severity
- Critical9.1CVSS 3.1, Critical
- EPSS
- 100%
- Published
- 9 Oct 2024
- Updated
- 17 Jun 2026
Description
Title, description and vendor guidance are quoted from the source records.
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
Weakness: CWE-89
Known exploited
Added to CISA KEV on 14 Nov 2024
Federal remediation due date: 5 Dec 2024
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit prediction
100% probability of exploitation in the next 30 days (percentile 100%).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected products
Patcharo shows this vulnerability for information but does not match versions for this product yet.
- Palo Alto Networks Expedition · 1.2.0 < 1.2.96
References
Provenance
Every fact on this page comes from the sources below. Nothing is written by an AI.
- Palo Alto Networks (CVE record)
- Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
- CISA Known Exploited Vulnerabilities
- CISA Known Exploited Vulnerabilities · 27 Sept 2026, 23:42 UTC · Parser patcharo-kev/1.0.0
- NVD
- NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
- FIRST EPSS
- FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0
Last verified: 28 Sept 2026, 02:31 UTC