Junglewise Threat Intelligence

CVE-2026-0309: Palo Alto Networks PAN-OS command injection in CLI with Luna HSM

CVE-2026-0309 · Severity: info · CVSS 7.1 · Published 2026-09-10

Vendors: Palo Alto Networks.

Executive brief

PAN-OS is the operating system that powers Palo Alto Networks firewalls, which protect network traffic and enforce security policies for enterprises. An authenticated administrator with CLI access to a firewall configured with a Luna Hardware Security Module can inject arbitrary commands and execute them with root privileges, potentially gaining complete control of the firewall. The risk is substantially reduced when CLI access is restricted to a small group of trusted administrators.

Technical details

This is an OS command injection vulnerability (CWE-78) in the PAN-OS CLI command handling, where special characters or metacharacters in user input are not properly neutralized before being passed to the OS shell. The vulnerability requires an authenticated administrator with local CLI access and a Luna HSM configured on the device; neither Panorama, Cloud NGFW, nor Prisma Access are affected. An authenticated attacker can exploit this to bypass system restrictions and execute arbitrary commands as root. Patches are available across all supported PAN-OS branches (10.2, 11.1, 11.2, and 12.1/12.2), with specific version guidance provided for each branch.

Affected products

  • Palo Alto Networks PAN-OS 10.2.0 through 10.2.18-h*, 11.1.0 through 11.1.16-h*, 11.2.0 through 11.2.13-h*, 12.1.2 through 12.1.9

Timeline

  • 2026-09-09: disclosed

References