CVE-2026-0308 PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
Description
A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.
This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).
Cloud NGFW and Prisma® Access are not affected by this vulnerability.
Product Status
| Versions | Affected | Unaffected |
|---|---|---|
| Cloud NGFW | None | All |
| PAN-OS 12.2 | None | All |
| PAN-OS 12.1 | < 12.1.10 | >= 12.1.10 |
| PAN-OS 11.2 | < 11.2.13-h2 | >= 11.2.13-h2 |
| PAN-OS 11.1 | < 11.1.16-h2 | >= 11.1.16-h2 |
| Prisma Access | None | All |
Required Configuration for Exposure
No special configuration is required to be affected by this issue.
Severity: LOW, Suggested Urgency: MODERATE
The risk is highest when you allow access to the management interface from external IP addresses on the internet.
LOW
- CVSS-BT: 1.1 /CVSS-B: 4.8 (CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)
You can reduce the risk of exploitation by restricting access to a jump box that is the only system allowed to access the management interface.
LOW
- CVSS-BT: 0.4 /CVSS-B: 2.4 (CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Amber)
Exploitation Status
Palo Alto Networks is not aware of any malicious exploitation of this issue.
Weakness Type and Impact
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Solution
| Version | Minor Version | Suggested Solution |
|---|---|---|
| Cloud NGFW | No action needed. | |
| PAN-OS 12.2 | No action needed. | |
| PAN-OS 12.1 |
12.1.2 through 12.1.9 | Upgrade to 12.1.10 or later. |
| PAN-OS 11.2 |
11.2.0 through 11.2.13 | Upgrade to 11.2.13-h2 or later. |
| PAN-OS 11.1 |
11.1.0 through 11.1.16 | Upgrade to 11.1.16-h2 or later. |
| All older unsupported PAN-OS versions | Upgrade to a supported fixed version. | |
| Prisma Access | No action needed. |
Workarounds and Mitigations
No known workarounds exist for this issue.
Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510040 and 510041 (from Applications and Threats content version 9145-10233 and later). For these Threat IDs to protect against attacks for this vulnerability:
- Route incoming traffic for the MGT port through a DP port, e.g., enabling management profile on a DP interface for management access.
- Replace the Certificate for Inbound Traffic Management.
- Decrypt inbound traffic to the management interface so the firewall can inspect it.
- Enable threat prevention on the inbound traffic to management services.
Please note that this Threat ID requires SSL Decryption.
Acknowledgments
Frequently Asked Questions
Q. Why do Threat Prevention signatures provide limited coverage?
Limited coverage in Threat Prevention means that while known attack patterns can be identified using the current Threat ID, variations may exist that cannot currently be detected. If this CVE and Required Configuration for Exposure impact your environment, we recommend upgrading to an unaffected version.
CPEs
cpe:2.3:o:palo_alto_networks:pan-os:12.1.9:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:12.1.8:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:12.1.7:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:12.1.6:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:12.1.5:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:12.1.4:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:12.1.3:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:12.1.2:*:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.2.13:h1:*:*:*:*:*:*
cpe:2.3:o:palo_alto_networks:pan-os:11.2.13:-:*:*:*:*:*:*
CPE Applicability
- cpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)12.1.0 and up to (excluding)12.1.10
- ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.2.13 and up to (excluding)11.2.13-h2
- ORcpe:2.3:o:palo_alto_networks:pan-os:*:*:*:*:*:*:*:* is vulnerable from (including)11.1.16 and up to (excluding)11.1.16-h2