Executive brief
PAN-OS is the operating system that powers Palo Alto Networks firewalls and Panorama management platforms, which are critical to network security and threat prevention. An authenticated administrator with malicious intent can inject JavaScript code into the firewall's web interface that persists and executes when other administrators access the system, potentially allowing them to steal credentials, manipulate firewall rules, or perform unauthorized actions. While an attacker must already have high-level administrative access, the ability to inject persistent scripts represents a significant integrity and confidentiality risk in environments managing critical network security.
Technical details
This is a stored cross-site scripting (CWE-79) vulnerability in the PAN-OS web management interface that allows authenticated administrators to inject and persist malicious JavaScript payloads. The vulnerability requires HIGH privileges (administrative access) and passive user interaction (another administrator viewing the affected page) to trigger payload execution. An attacker with admin credentials can store JavaScript in the web interface which executes in the browsers of other administrators accessing the system, potentially compromising their sessions or enabling lateral attacks within the management plane. Patches are available: upgrade to PAN-OS 12.1.10+, 11.2.13-h2+, or 11.1.16-h2+. Cloud NGFW and Prisma Access are unaffected.
Affected products
- Palo Alto Networks PAN-OS PAN-OS 11.1.0–11.1.16, 11.2.0–11.2.13, 12.1.2–12.1.9
- Palo Alto Networks PA-Series PAN-OS 11.1.0–11.1.16, 11.2.0–11.2.13, 12.1.2–12.1.9
- Palo Alto Networks VM-Series PAN-OS 11.1.0–11.1.16, 11.2.0–11.2.13, 12.1.2–12.1.9
- Palo Alto Networks Panorama PAN-OS 11.1.0–11.1.16, 11.2.0–11.2.13, 12.1.2–12.1.9
Timeline
- 2026-09-09: disclosed
- 2026-09-10: other: Advisory published