Vulnerability Description
When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operator group. * Installations based on Panorama Suite 2025 (25.00.004) are vulnerable unless update PS-2500-00-0357 (or higher) is installed * Installations based on Panorama Suite 2025 Updated Dec. 25 (25.10.007) are not vulnerable Please refer to security bulletin BS-036, available on the Panorama CSIRT website: https://my.codra.net/en-gb/csirt.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Codra | Panorama Collaborative Operation \& Execution | 25.00.004 |
| Codra | Panorama Com | 25.00.004 |
| Codra | Panorama E2 | 25.00.004 |
| Codra | Panorama H2 | 25.00.004 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-4761?
CVE-2026-4761 is a vulnerability with a CVSS score of 7.5 (HIGH). When a certificate and its private key are installed in the Windows machine certificate store using Network and Security tool, access rights to the private key are unnecessarily granted to the operato...
How severe is CVE-2026-4761?
CVE-2026-4761 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-4761?
Check the references section above for vendor advisories and patch information. Affected products include: Codra Panorama Collaborative Operation \& Execution, Codra Panorama Com, Codra Panorama E2, Codra Panorama H2.