CVE-2026-0308 PUBLISHED

PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

Assigner: palo_alto
Reserved: 03.11.2025 Published: 10.09.2026 Updated: 10.09.2026

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 1.1

The risk is highest when you allow access to the management interface from external IP addresses on the internet.

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 0.4

You can reduce the risk of exploitation by restricting access to a jump box that is the only system allowed to access the management interface.

Product Status

Vendor Palo Alto Networks
Product Cloud NGFW
Versions Default: unaffected
  • Version All is unaffected
Vendor Palo Alto Networks
Product PAN-OS
Versions Default: unaffected
  • unaffected from 12.2.0 to 12.2.3 (excl.)
  • affected from 12.1.0 to 12.1.10 (excl.)
  • affected from 11.2.0 to 11.2.13-h2 (excl.)
  • affected from 11.1.0 to 11.1.16-h2 (excl.)
Vendor Palo Alto Networks
Product Prisma Access
Versions Default: affected
  • unaffected from All to 12.1.4-h10 (excl.)

Affected Configurations

No special configuration is required to be affected by this issue.

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Workarounds

No known workarounds exist for this issue.

Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510040 and 510041 (from Applications and Threats content version 9145-10233 and later). For these Threat IDs to protect against attacks for this vulnerability:

  • Route incoming traffic for the MGT port through a DP port https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id59206398-3dab-4b2f-9b4b-7ea500d036ba , e.g., enabling management profile on a DP interface for management access.

  • Replace the Certificate for Inbound Traffic Management https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#id112f7714-8995-4496-bbf9-781e63dec71c .

  • Decrypt inbound traffic to the management interface so the firewall can inspect it https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices#idbbd82587-17a2-42b4-9245-d3714e1e13a2 .
  • Enable threat prevention on the inbound traffic to management services.

Please note that this Threat ID requires SSL Decryption.

Credits

  • Michał Skowron and Tomasz Stachowicz of ING Hubs Poland and James Otten (internal reporter) finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE

Impacts

  • CAPEC-592 Stored XSS