Junglewise Threat Intelligence

CVE-2026-0286: Palo Alto Networks PAN-OS command injection in management plane CLI

CVE-2026-0286 · Severity: info · CVSS 6 · Published 2026-07-09

Vendors: Palo Alto Networks.

Executive brief

A security vulnerability has been identified in the management software for Palo Alto Networks firewalls and Panorama management servers. An authorized administrator with high-level access could exploit this flaw to take full control of the underlying operating system. While this requires existing administrative credentials, a successful exploit could lead to a complete compromise of the device's security and integrity.

Technical details

An OS command injection vulnerability (CWE-78) exists in the management plane of Palo Alto Networks PAN-OS. The flaw allows an authenticated administrator with high privileges (PR:H) to bypass security restrictions via the Command Line Interface (CLI) and execute arbitrary commands with root-level permissions. The vulnerability affects PA-Series, VM-Series, and Panorama platforms, but does not impact Cloud NGFW or Prisma Access. Attackers can reach the vulnerable component over the network if management access is exposed. Palo Alto Networks has released patches for various branches including 12.1, 11.2, 11.1, and 10.2.

Affected products

  • Palo Alto Networks PAN-OS 12.1 < 12.1.4-h8, 12.1.5 < 12.1.7-h2, 11.2 < 11.2.4-h20, 11.2.5 < 11.2.7-h18, 11.2.8 < 11.2.10-h11, 11.1 < 11.1.4-h35, 10.2 < 10.2.7-h36

Timeline

  • 2026-07-08: disclosed: Discovered externally by TRAPA Security and internal teams.
  • 2026-07-08: advisory
  • 2026-07-09: patched: NVD publication date.

References