CVE-2026-0272 PUBLISHED

PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)

Assigner: palo_alto
Reserved: 03.11.2025 Published: 10.06.2026 Updated: 11.06.2026

A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges.

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:C/RE:M/U:Amber
CVSS Score: 6

The risk is highest when you allow access to the management interface from external IP addresses on the internet.

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:C/RE:M/U:Amber
CVSS Score: 5.6

You can reduce the risk of exploitation by restricting access to a jump box that is the only system allowed to access the management interface.

Product Status

Vendor Palo Alto Networks
Product Cloud NGFW
Versions Default: unaffected
  • Version All is unaffected
Vendor Palo Alto Networks
Product PAN-OS
Versions Default: unaffected
  • affected from 12.1.0 to 12.1.4-h7 (excl.)
  • affected from 11.2.0 to 11.2.4-h18 (excl.)
  • affected from 11.1.0 to 11.1.4-h34 (excl.)
  • affected from 10.2.0 to 10.2.7-h35 (excl.)
Vendor Palo Alto Networks
Product Prisma Access
Versions Default: unaffected
  • Version All is unaffected

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Credits

  • Palo Alto Networks thanks an external reporter, Frigo, for discovering and reporting this issue. other

References

Problem Types

  • CWE-862 Missing Authorization CWE

Impacts

  • CAPEC-233 Privilege Escalation