Executive brief
A security vulnerability exists in the management interface of Palo Alto Networks firewalls and Panorama management servers. This flaw allows an administrator with high-level access to inject malicious scripts into the web interface. If another user views the affected page, the script could execute in their browser, potentially leading to unauthorized actions or data exposure within the management session.
Technical details
A stored cross-site scripting (XSS) vulnerability (CWE-79) exists in the web interface of Palo Alto Networks PAN-OS. The flaw is caused by improper neutralization of input during web page generation, allowing an authenticated administrator with high privileges (PR:H) to store a malicious JavaScript payload. Execution of the payload requires a victim user to interact with the specific part of the web interface where the payload is stored (UI:P). This affects PA-Series, VM-Series, and Panorama platforms. Fixed versions have been released across the 10.2, 11.1, 11.2, and 12.1 release trains. Threat Prevention identity 510020 can be used as a mitigation if specific decryption and routing configurations are met.
Affected products
- Palo Alto Networks PAN-OS 12.1 < 12.1.4-h5, 12.1 < 12.1.7, 11.2 < 11.2.4-h17, 11.2 < 11.2.7-h13, 11.2 < 11.2.10-h6, 11.2 < 11.2.12, 11.1 < 11.1.4-h33, 11.1 < 11.1.6-h32, 11.1 < 11.1.7-h6, 11.1 < 11.1.10-h25, 11.1 < 11.1.13-h5, 11.1 < 11.1.15, 10.2 < 10.2.7-h34, 10.2 < 10.2.10-h36, 10.2 < 10.2.13-h21, 10.2 < 10.2.16-h7, 10.2 < 10.2.18-h6
- Siemens RUGGEDCOM APE1808 All versions with Palo Alto Networks Virtual NGFW
Timeline
- 2026-05-12: advisory: Siemens published initial advisory SSA-967325
- 2026-05-13: disclosed: Palo Alto Networks published the vulnerability details
- 2026-05-28: other: Advisory updated by Palo Alto Networks
- 2026-06-09: other: Siemens advisory updated to V1.1