Executive brief
Palo Alto Networks PAN-OS is the operating system used in firewalls and management appliances to secure corporate networks. A vulnerability exists that allows an administrator who already has login access to bypass security restrictions and take full control of the system as a 'root' user. While this requires existing administrative credentials, an exploit could allow a rogue insider or an attacker who has compromised an admin account to permanently compromise the firewall or disrupt network operations.
Technical details
Multiple OS command injection vulnerabilities (CWE-78) exist in the PAN-OS software. An authenticated attacker with administrative privileges can exploit these flaws via the Command Line Interface (CLI) or the Web User Interface (Web UI) to bypass restricted shells or environment limitations. Successful exploitation allows the execution of arbitrary commands with root-level privileges on the underlying operating system. The vulnerability affects PA-Series, VM-Series, and Panorama platforms. Palo Alto Networks has released several maintenance releases (e.g., 12.1.4-h5, 11.2.12, 11.1.15, 10.2.18-h6) to address these issues. Mitigation involves restricting management access to trusted internal IP addresses and limiting the number of users with administrative CLI access.
Affected products
- Palo Alto Networks PAN-OS 12.1 < 12.1.4-h5, 12.1.5 through 12.1.6, 11.2 < 11.2.4-h17, 11.2.5 through 11.2.7-h13, 11.2.8 through 11.2.10-h6, 11.2.11, 11.1 < 11.1.4-h33, 11.1.5 through 11.1.6-h32, 11.1.7 through 11.1.7-h6, 11.1.8 through 11.1.10-h25, 11.1.11 through 11.1.13-h5, 11.1.14, 10.2 < 10.2.7-h34, 10.2.8 through 10.2.10-h36, 10.2.11 through 10.2.13-h21, 10.2.14 through 10.2.16-h7, 10.2.17 through 10.2.18-h6
- Siemens RUGGEDCOM APE1808 All versions with Palo Alto Networks Virtual NGFW
Timeline
- 2026-05-13: advisory: Initial advisory published by Palo Alto Networks
- 2026-05-28: other: Advisory updated by Palo Alto Networks
- 2026-06-09: other: Siemens advisory updated regarding RUGGEDCOM APE1808 devices