🔐 CVE Alert

CVE-2025-4235

UNKNOWN 0.0

User-ID Credential Agent: Cleartext Exposure of Service Account password

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An information exposure vulnerability in the Palo Alto Networks User-ID Credential Agent (Windows-based) can expose the service account password under specific non-default configurations. This allows an unprivileged Domain User to escalate privileges by exploiting the account’s permissions. The impact varies by configuration: * Minimally Privileged Accounts: Enable disruption of User-ID Credential Agent operations (e.g., uninstalling or disabling the agent service), weakening network security policies that leverage Credential Phishing Prevention https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/credential-phishing-prevention under a Domain Credential Filter https://docs.paloaltonetworks.com/advanced-url-filtering/administration/url-filtering-features/credential-phishing-prevention/methods-to-check-for-corporate-credential-submissions configuration. * Elevated Accounts (Server Operator, Domain Join, Legacy Features): Permit increased impacts, including server control (e.g., shutdown/restart), domain manipulation (e.g., rogue computer objects), and network compromise via reconnaissance or client probing.

CWE CWE-497
Vendor palo alto networks
Product user-id credential agent
Published Sep 12, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for palo alto networks user-id credential agent

Be the first to know when new unknown vulnerabilities affecting palo alto networks user-id credential agent are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Palo Alto Networks / User-ID Credential Agent
All versions affected

References

NVD ↗ CVE.org ↗ EPSS Data ↗
security.paloaltonetworks.com: https://security.paloaltonetworks.com/CVE-2025-4235

Credits

Palo Alto Networks thanks an external reporter for discovering and reporting this issue.