> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exposure-and-vulnerability-management-permissions/vulnerability-management-permissions.md).

# Vulnerability Management permissions

Controls access to Vulnerability Management, which provides a centralized view of vulnerabilities across your organization to track, prioritize, and remediate discovered CVEs and exposures.

{% hint style="info" %}

### Note

Requires a Cloud Posture Security, Cloud Runtime Security, Attack Surface Management (ASM), Exposure Management, or Cortex XSIAM Premium license. How users access and utilize these features depends on your license.

* Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium licenses: Go to **Posture Management** → **Vulnerability Management**. Grants access to Vulnerability Issues, Vulnerable Assets, Vulnerabilities by CVE, Vulnerability Intelligence, and Emerging Vulnerabilities.
* Exposure Management license: Go to **Exposure Management** → **Vulnerability Management**. Contact Customer Support to enable this feature.
* ASM license (without other licenses): Go to **Modules** → **Attak Surface.**. Grants access only to **Vulnerability Policies**.
  {% endhint %}

For more information, see [Vulnerability Management](/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management.md).

| Permission | Description                                                                                                                               | Roles Example                                                                                                                                                                                                                                                          |
| ---------- | ----------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| None       | No access to Vulnerability Management pages, such as Vulnerability Issues, Findings, CVEs, and Vulnerability Policies.                    |                                                                                                                                                                                                                                                                        |
| View       | Read-only access to Vulnerability Management pages, such as Vulnerability Issues, Findings, CVEs, and Vulnerability Policies.             | <ul><li>SOC Tier 1 and 2 Analysts: Needs visibility into vulnerabilities for initial triage; should not modify rules or policies.</li><li>Threat Hunter: Needs read access for threat research and correlation; typically does not modify rules or policies.</li></ul> |
| View/Edit  | Full access to manage vulnerability issues (change status, assign, change severity), create/edit vulnerability policies (where relevant). | <ul><li>SOC Tier 3 Analyst: Senior analysts who can manage vulnerability issue lifecycle.</li><li>Security Engineer: Configures vulnerability remediation workflows.</li></ul>                                                                                         |

**Required and recommended permissions**

To effectively prioritize and respond to vulnerabilities, administrators and analysts require visibility into the underlying attack surface rules, active tests, and resulting security issues. Consider adding the following permissions.

| Permission            | Permission Level  | Reason                                                                                                                                                                                                                                                                                                                                                                          |
| --------------------- | ----------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cases & Issues        | View or View/Edit | <ul><li>View: Strongly recommended to view cases/issues linked to vulnerability issues.</li><li>View/Edit: Recommended to actively triage and respond to issues linked to exposure findings.</li></ul>                                                                                                                                                                          |
| Attack Surface Rules  | View              | Strongly recommended to view the attack surface rules referenced in the vulnerability context.                                                                                                                                                                                                                                                                                  |
| Vulnerability Testing | View              | Recommended to view vulnerability testing evidence in vulnerability issue details.                                                                                                                                                                                                                                                                                              |
| Exposure Management   | View              | Strongly Recommended for Security Controls view and broader Exposure Management navigation. Without this, users cannot see compensating controls or effectiveness data linked to vulnerability issues. View/Edit: Recommended for editing the Security Controls effectiveness rules. Only needed if the user should manage security controls, not just view vulnerability data. |
| Asset Inventory       | View              | Recommended. Provides necessary context regarding which specific assets are affected by the security control gaps.                                                                                                                                                                                                                                                              |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/reference-and-developer-docs/role-based-access-control/exposure-and-vulnerability-management-permissions/vulnerability-management-permissions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
