Junglewise Threat Intelligence

CVE-2026-0279: Palo Alto Networks PAN-OS XSS in GlobalProtect and Authentication Portal

CVE-2026-0279 · Severity: info · CVSS 5.3 · Published 2026-07-09

Technologies: Palo Alto Networks Prisma Access. Vendors: Palo Alto Networks.

Executive brief

Palo Alto Networks firewalls and management systems are affected by security flaws in their authentication and VPN portals. These vulnerabilities could allow an unauthorized person to run malicious scripts in a user's browser if they visit a compromised link. This could lead to unauthorized actions being performed on behalf of the user or the theft of session information.

Technical details

Multiple cross-site scripting (XSS) vulnerabilities (CWE-79) exist in the User-ID Authentication Portal (Captive Portal), GlobalProtect gateway/portal, and Clientless VPN features of PAN-OS. The root cause is improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit these flaws by enticing a user to interact with a malicious link or visiting a compromised portal page, leading to the execution of arbitrary JavaScript. While the vendor rates the base severity as Low (CVSS 1.3/5.3), the risk is elevated if management interfaces are exposed to the internet. Fixed versions include PAN-OS 12.1.8, 11.2.13, and 11.1.16.

Affected products

  • Palo Alto Networks PAN-OS 12.1 < 12.1.8, 11.2 < 11.2.13, 11.1 < 11.1.16, 10.2 (all versions)
  • Palo Alto Networks Prisma Access 12.1 < 12.1.8, 11.2 (all versions), 10.2 (all versions)

Timeline

  • 2026-07-08: disclosed: Discovered internally by Palo Alto Networks
  • 2026-07-09: advisory

References

Related threats