CVE-2026-0309 PUBLISHED

PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration

Assigner: palo_alto
Reserved: 03.11.2025 Published: 10.09.2026 Updated: 10.09.2026

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM).

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS Score: 4

Product Status

Vendor Palo Alto Networks
Product Cloud NGFW
Versions Default: unaffected
  • Version All is unaffected
Vendor Palo Alto Networks
Product PAN-OS
Versions Default: unaffected
  • affected from 12.2.0 to 12.2.3 (excl.)
  • affected from 12.1.0 to 12.1.4-h10 (excl.)
  • affected from 11.2.0 to 11.2.4-h21 (excl.)
  • affected from 11.1.0 to 11.1.4-h36 (excl.)
  • affected from 10.2.0 to 10.2.7-h37 (excl.)
Vendor Palo Alto Networks
Product Prisma Access
Versions Default: unaffected
  • unaffected from All to 12.1.4-h10 (excl.)

Exploits

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Credits

  • François Rigault finder

References

Problem Types

  • CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE

Impacts

  • CAPEC-88 OS Command Injection