Answer in brief
CVE-2024-5910 records a High severity vulnerability in Expedition: Missing Authentication Leads to Admin Account Takeover. The current sources mark it as known exploited. The current feed maps paloaltonetworks/expedition (generic), Palo Alto Networks/Expedition (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps paloaltonetworks/expedition (generic), Palo Alto Networks/Expedition (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| paloaltonetworks/expeditiongeneric | >=1.2 <1.2.92 | 1.2.92 |
| Palo Alto Networks/Expeditiongeneric | >=1.2 <1.2.92 | 1.2.92 |
Published upstream
Jul 10, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Nov 7, 2024
Evidence: source:kev:kev:kev:recordMissing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-5910 records a High severity vulnerability in Expedition: Missing Authentication Leads to Admin Account Takeover. The current sources mark it as known exploited. The current feed maps paloaltonetworks/expedition (generic), Palo Alto Networks/Expedition (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps paloaltonetworks/expedition (generic), Palo Alto Networks/Expedition (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| paloaltonetworks/expeditiongeneric | >=1.2 <1.2.92 | 1.2.92 |
| Palo Alto Networks/Expeditiongeneric | >=1.2 <1.2.92 | 1.2.92 |
Published upstream
Jul 10, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Nov 7, 2024
Evidence: source:kev:kev:kev:recordMissing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
Quoted source text, attributed separately from HOL analysis.