Executive brief
A vulnerability in Palo Alto Networks firewalls and management systems allows an unauthorized person to delete temporary files via the web management interface. While this could disrupt some system operations, it does not allow the attacker to access sensitive data or take full control of the device. The risk is significantly lower for organizations that follow best practices by restricting management access to trusted internal networks.
Technical details
An improper input validation vulnerability (CWE-20) in the PAN-OS management web interface allows an unauthenticated remote attacker with network access to delete files within a temporary directory. The root cause is related to insufficient validation of user-supplied input used in file manipulation operations (CAPEC-165). While the impact is limited to temporary files, it could potentially lead to a denial-of-service condition for specific web interface functions. The vulnerability affects PA-Series, VM-Series, and Panorama platforms. Patches are available in PAN-OS versions 12.1.8, 11.2.13, and 11.1.16.
Affected products
- Palo Alto Networks PAN-OS 12.1 < 12.1.8, 11.2 < 11.2.13, 11.1 < 11.1.16, 10.2 (all versions)
- Palo Alto Networks Panorama All versions running affected PAN-OS releases
Timeline
- 2026-07-08: disclosed: Discovered internally by Palo Alto Networks
- 2026-07-08: advisory: Initial publication of CVE-2026-0282