Junglewise Threat Intelligence

CVE-2026-0273: Palo Alto Networks PAN-OS command injection in CLI or Web UI

CVE-2026-0273 · Severity: info · CVSS 6.1 · Published 2026-06-10

Vendors: Palo Alto Networks.

Executive brief

A vulnerability in Palo Alto Networks firewalls and management systems allows an authorized administrator to bypass security restrictions. By exploiting this flaw, a user with administrative credentials can take full control of the device and run unauthorized commands with the highest level of system privileges (root). This could lead to a complete compromise of the network security infrastructure, though the risk is limited to individuals who already have administrative access.

Technical details

A command injection vulnerability (CWE-78) exists in the PAN-OS software used by PA-Series, VM-Series, and Panorama platforms. The flaw allows an authenticated administrator with access to the Command Line Interface (CLI) or Web Interface (Web UI) to bypass system restrictions. By injecting malicious OS commands, the attacker can achieve root-level execution on the underlying operating system. While the attack vector is listed as network-reachable, it requires high privileges (PR:H). Palo Alto Networks has released patches across multiple major versions (10.2, 11.1, 11.2, 12.1) to address this issue.

Affected products

  • Palo Alto Networks PAN-OS 12.1 < 12.1.4-h7, 12.1 < 12.1.7, 11.2 < 11.2.4-h18, 11.2 < 11.2.7-h16, 11.2 < 11.2.10-h9, 11.2 < 11.2.12, 11.1 < 11.1.4-h34, 11.1 < 11.1.6-h33, 11.1 < 11.1.7-h7, 11.1 < 11.1.10-h27, 11.1 < 11.1.13-h7, 11.1 < 11.1.15, 10.2 < 10.2.7-h35, 10.2 < 10.2.10-h37, 10.2 < 10.2.13-h22, 10.2 < 10.2.16-h8, 10.2 < 10.2.18-h7

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory
  • 2026-06-10: patched

References