Palo Alto Networks Security Advisories / CVE-2026-0308

CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface

Urgency MODERATE

047910
Severity 1.1 · LOW
Exploit Maturity UNREPORTED
Response Effort MODERATE
Recovery USER
Value Density DIFFUSE
Attack Vector NETWORK
Attack Complexity LOW
Attack Requirements NONE
Automatable NO
User Interaction PASSIVE
Product Confidentiality LOW
Product Integrity LOW
Product Availability NONE
Privileges Required HIGH
Subsequent Confidentiality NONE
Subsequent Integrity NONE
Subsequent Availability NONE

Description

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Product Status

VersionsAffectedUnaffected
Cloud NGFWNone
All
PAN-OS 12.2None
All
PAN-OS 12.1< 12.1.10
>= 12.1.10
PAN-OS 11.2< 11.2.13-h2
>= 11.2.13-h2
PAN-OS 11.1< 11.1.16-h2
>= 11.1.16-h2
Prisma AccessNone
All

Required Configuration for Exposure

No special configuration is required to be affected by this issue.

Severity: LOW, Suggested Urgency: MODERATE

The risk is highest when you allow access to the management interface from external IP addresses on the internet.
LOW - CVSS-BT: 1.1 /CVSS-B: 4.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)

You can reduce the risk of exploitation by restricting access to a jump box that is the only system allowed to access the management interface.
LOW - CVSS-BT: 0.4 /CVSS-B: 2.4 (CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)

Exploitation Status

Palo Alto Networks is not aware of any malicious exploitation of this issue.

Weakness Type and Impact

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CAPEC-592 Stored XSS

Solution

Version
Minor Version
Suggested Solution
Cloud NGFW  No action needed.
PAN-OS 12.2  No action needed.
PAN-OS 12.1
12.1.2 through 12.1.9 Upgrade to 12.1.10 or later.
PAN-OS 11.2
11.2.0 through 11.2.13 Upgrade to 11.2.13-h2 or later.
PAN-OS 11.1
11.1.0 through 11.1.16 Upgrade to 11.1.16-h2 or later.
All older
unsupported
PAN-OS versions
 Upgrade to a supported fixed version.
Prisma AccessNo action needed.

Workarounds and Mitigations

No known workarounds exist for this issue.

Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510040 and 510041 (from Applications and Threats content version 9145-10233 and later). For these Threat IDs to protect against attacks for this vulnerability:

Please note that this Threat ID requires SSL Decryption.

Acknowledgments

Palo Alto Networks thanks Michał Skowron and Tomasz Stachowicz of ING Hubs Poland and James Otten (internal reporter) for discovering and reporting this issue.

Frequently Asked Questions

Q. Why do Threat Prevention signatures provide limited coverage?

Limited coverage in Threat Prevention means that while known attack patterns can be identified using the current Threat ID, variations may exist that cannot currently be detected. If this CVE and Required Configuration for Exposure impact your environment, we recommend upgrading to an unaffected version.

CPEs

cpe:2.3:o:palo_alto_networks:pan-os:12.1.9:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.8:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.7:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.6:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.5:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.4:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.3:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:12.1.2:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.13:h1:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.13:-:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.12:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.11:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.10:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.9:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.8:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.7:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.6:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.5:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.4:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.3:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.2:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.1:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.2.0:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.16:h1:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.16:-:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.15:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.14:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.13:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.12:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.11:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.10:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.9:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.8:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.6:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.5:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.4:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.3:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.2:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.1:*:*:*:*:*:*:*

cpe:2.3:o:palo_alto_networks:pan-os:11.1.0:*:*:*:*:*:*:*

CPE Applicability

Timeline

Initial Publication
© 2026 Palo Alto Networks, Inc. All rights reserved.