CVE-2025-0138 - CVE House
Back to Database
Status published Low CVE-2025-0138

Prisma Cloud Compute Edition: Insufficient Session Expiration Vulnerability in the Web Interface

Vulnerability Description

Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not affected by this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0138

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Maciej Pypec of ING

Affected Vendor

Palo Alto Networks

View all reports →

Affected Software

Prisma Cloud Compute Edition, Compute in Prisma Cloud Enterprise Edition
Vulnerable Versions:
1, All

Timeline

Official Publish: May 14th, 2025
Last Modified: June 23rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)