Skip to content
All vulnerabilities
CVE-2026-0286

PAN-OS: Authenticated Command Injection in CLI

Severity
High7.2CVSS 3.1, High
EPSS
2%
Published
9 Jul 2026
Updated
11 Aug 2026

Description

Title, description and vendor guidance are quoted from the source records.

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

Weakness: CWE-78

Known exploited

Not listed in CISA KEV as of the last check.

Exploit prediction

2% probability of exploitation in the next 30 days (percentile 76%).

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

What the source states, per branch

Versions matched by Patcharo

Palo Alto Networks PAN-OSSource: Palo Alto Networks (CVE record)

BranchAffectedFixed in
12.1
>= 12.1.0, < 12.1.4-h8
>= 12.1.5, < 12.1.7-h2
12.1.4-h8
12.1.7-h2
11.2
>= 11.2.0, < 11.2.4-h20
>= 11.2.5, < 11.2.7-h18
>= 11.2.8, < 11.2.10-h11
>= 11.2.11, < 11.2.13
11.2.4-h20
11.2.7-h18
11.2.10-h11
11.2.13
11.1
>= 11.1.0, < 11.1.4-h35
>= 11.1.5, < 11.1.6-h35
>= 11.1.7, < 11.1.7-h8
>= 11.1.8, < 11.1.10-h30
>= 11.1.11, < 11.1.13-h9
>= 11.1.14, < 11.1.16
11.1.4-h35
11.1.6-h35
11.1.7-h8
11.1.10-h30
11.1.13-h9
11.1.16
10.2
>= 10.2.0, < 10.2.7-h36
>= 10.2.8, < 10.2.10-h39
>= 10.2.11, < 10.2.13-h23
>= 10.2.14, < 10.2.16-h9
>= 10.2.17, < 10.2.18-h8
10.2.7-h36
10.2.10-h39
10.2.13-h23
10.2.16-h9
10.2.18-h8

Versions not listed are stated unaffected by the vendor.

Workaround / Vendor remediation

Workaround · PAN-OS

Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510036 (from Applications and Threats content version 9122-10145 and later). For these Threat IDs to protect against attacks for this vulnerability: * Route incoming traffic for the MGT port through a DP port https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id59206398-3dab-4b2f-9b4b-7ea500d036ba , e.g., enabling management profile on a DP interface for management access. * Replace the Certificate for Inbound Traffic Management https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id112f7714-8995-4496-bbf9-781e63dec71c . …

Vendor remediation · PAN-OS

Version Minor Version Suggested Solution Cloud NGFW All No action needed. PAN-OS 12.1 12.1.5 through 12.1.7-h* Upgrade to 12.1.7-h2 or 12.1.8 or later. 12.1.2 through 12.1.4-h* Upgrade to 12.1.4-h8 or 12.1.8 or later. PAN-OS 11.2 11.2.11 through 11.2.12 Upgrade to 11.2.13 or later. 11.2.8 through 11.2.10-h* Upgrade to 11.2.10-h11 or 11.2.13 or later. 11.2.5 through 11.2.7-h* Upgrade to 11.2.7-h18 or 11.2.13 or later. 11.2.0 through 11.2.4-h* Upgrade to 11.2.4-h20 or 11.2.13 or later. PAN-OS 11.1 11.1.14 through 11.1.15 Upgrade to 11.1.16 or later. 11.1.11 through 11.1.13-h* Upgrade to 11.1.13-h9 or 11.1.16 or later. 11.1.8 through 11.1.10-h* Upgrade to 11.1.10-h30 or 11.1.16 or later. 11.1.7 through 11.1.7-h* Upgrade to 11.1.7-h8 or 11.1.16 or later. 11.1.5 through 11.1.6-h* Upgrade to 11.1.6-h35 or 11.1.16 or later. 11.1.0 through 11.1.4-h* Upgrade to 11.1.4-h35 or 11.1.16 or later. PA…

References

Provenance

Every fact on this page comes from the sources below. Nothing is written by an AI.

Palo Alto Networks (CVE record)
Palo Alto Networks (CVE record) · 27 Sept 2026, 23:46 UTC · Parser patcharo-cve5/1.1.0
NVD
NVD · 27 Sept 2026, 23:44 UTC · Parser patcharo-nvd/1.0.0
FIRST EPSS
FIRST EPSS · 27 Sept 2026, 23:46 UTC · Parser patcharo-epss/1.0.0

Last verified: 28 Sept 2026, 02:31 UTC