Expedition
CVE-2024-5910: Missing Authentication Leads to Admin Account Takeover
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Expedition 1.2 | 1.2.92 or later |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.
Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
Workarounds
Ensure network access to Expedition is restricted to authorized users, hosts, or networks.
Exploitation
Palo Alto Networks is aware of reports from CISA that there is evidence of active exploitation for this CVE. More information can be found at https://www.cisa.gov/news-events/alerts/2024/11/07/cisa-adds-four-known-exploited-vulnerabilities-catalog.
CISA lists this CVE as exploited in the wild since 7 Nov 2024.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.