Junglewise Threat Intelligence

CVE-2026-0266: Palo Alto Networks PAN-OS stored XSS in web interface

CVE-2026-0266 · Severity: info · CVSS 4.8 · Published 2026-06-10

Vendors: Palo Alto Networks.

Executive brief

A security vulnerability exists in the management software for Palo Alto Networks firewalls and Panorama management appliances. An administrator with high-level access could upload malicious scripts that execute when other users visit the management interface. While this requires existing administrative privileges, it could be used to target other administrators or disrupt management operations.

Technical details

A stored cross-site scripting (XSS) vulnerability (CWE-79) exists in the web interface of Palo Alto Networks PAN-OS. The flaw allows an authenticated administrator with high privileges (PR:H) to store a malicious JavaScript payload via the management console. The vulnerability is triggered when another user views the affected page in the web interface (UI:P). This issue affects PA-Series, VM-Series, and Panorama platforms. Palo Alto Networks has released patches for versions 11.1, 11.2, and 12.1; users on 10.2 are advised to upgrade to a later supported branch.

Affected products

  • Palo Alto Networks PAN-OS 12.1 < 12.1.5, 11.2 < 11.2.11, 11.1 < 11.1.14, 10.2 (all versions)

Timeline

  • 2026-06-10: disclosed: Initial publication of the advisory.
  • 2026-06-10: patched

References