Junglewise Threat Intelligence

CVE-2026-0272: Palo Alto Networks PAN-OS privilege escalation in CLI

CVE-2026-0272 · Severity: info · CVSS 6 · Published 2026-06-10

Vendors: Palo Alto Networks.

Executive brief

A security vulnerability in Palo Alto Networks firewalls and management systems could allow an authorized administrator to gain full root-level control over the device. While this requires the attacker to already have administrative credentials, it allows them to bypass intended restrictions and perform any action on the system. This could lead to a complete compromise of the security appliance and the network traffic it manages.

Technical details

A privilege escalation vulnerability exists in the Command Line Interface (CLI) of Palo Alto Networks PAN-OS due to missing authorization (CWE-862). An authenticated administrator with CLI access can exploit this flaw to execute commands with root privileges. The vulnerability affects PA-Series, VM-Series firewalls, and Panorama management platforms. While the attack vector is listed as network-reachable via the management interface, it requires high privileges (PR:H) to execute. Palo Alto Networks has released patches across multiple PAN-OS release trains (10.2, 11.1, 11.2, and 12.1) to address this issue.

Affected products

  • Palo Alto Networks PAN-OS 12.1 < 12.1.4-h7, 12.1 < 12.1.5, 11.2 < 11.2.4-h18, 11.2 < 11.2.7-h16, 11.2 < 11.2.10-h9, 11.2 < 11.2.11, 11.1 < 11.1.4-h34, 11.1 < 11.1.6-h33, 11.1 < 11.1.7-h7, 11.1 < 11.1.10-h27, 11.1 < 11.1.13-h7, 11.1 < 11.1.14, 10.2 < 10.2.7-h35, 10.2 < 10.2.10-h37, 10.2 < 10.2.13-h22, 10.2 < 10.2.16-h8, 10.2 < 10.2.18-h5

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: patched
  • 2026-06-10: advisory

References