PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities

MonitorCVSS 5.3CVE-2026-0279Jul 8, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

Multiple cross-site scripting vulnerabilities in the User-ID Authentication Portal, GlobalProtect gateway/portal, and Clientless VPN features of Palo Alto Networks PAN-OS allow an unauthenticated attacker to inject and execute malicious JavaScript in user browsers. The vulnerabilities affect PAN-OS on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not affected. Security risk is minimized when management interfaces and portal access are restricted to trusted internal IP addresses only.

What this means
What could happen
An unauthenticated attacker can inject malicious JavaScript into the User-ID Authentication Portal, GlobalProtect gateway/portal, or Clientless VPN interfaces. This could allow account hijacking, credential theft, or redirection of users to malicious sites, potentially compromising firewall management credentials and administrative access.
Who's at risk
Firewall and network operations teams managing Palo Alto Networks PA-Series, VM-Series firewalls, or Panorama appliances in environments where the management interface, User-ID Authentication Portal, GlobalProtect, or Clientless VPN is reachable from user networks or the internet. This affects organizations using these components for remote access or portal-based authentication.
How it could be exploited
An attacker crafts a malicious URL containing JavaScript payload and sends it to firewall users accessing the User-ID Authentication Portal, GlobalProtect gateway, or Clientless VPN interface (typically accessed over the management or user-facing networks). When a user clicks the link or is redirected, the JavaScript executes in their browser, allowing the attacker to steal session tokens, credentials, or redirect to a phishing site.
Prerequisites
  • <parameter name="prerequisites"> <parameter name="item">Network reachability to the User-ID Authentication Portal, GlobalProtect gateway/portal, or Clientless VPN interface (typically management IP or user-accessible VPN endpoint)
remotely exploitableno authentication required for XSS injectionlow complexityaffects management/administrative accessdefault configuration may expose portal to untrusted networks
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
PAN-OSBelow 12.1.812.1.8+
Prisma AccessBelow 11.2.1311.2.13+
Remediation & Mitigation
0/5
Do now
0/2
HARDENINGRestrict management interface access to trusted internal IP addresses only via firewall rules or administrative access lists
HARDENINGDisable or restrict access to User-ID Authentication Portal, GlobalProtect gateway/portal, and Clientless VPN from untrusted networks if not required for business operations
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

PAN-OS
HOTFIXUpdate PAN-OS to version 12.1.8 or later
Prisma Access
HOTFIXUpdate Prisma Access to version 11.2.13 or later
Long-term hardening
0/1
HARDENINGReview and audit current management access controls against Palo Alto Networks administrative access best practices
API: /api/v1/advisories/a9a7da1b-e01e-45c7-a614-5a23b62ba623

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities | CVSS 5.3 - OTPulse