PAN-OS: File Deletion Vulnerability in Management Web Interface

MonitorCVSS 6.9CVE-2026-0282Jul 8, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary

A file deletion vulnerability in PAN-OS software enables an unauthenticated attacker with network access to the management web interface to delete files from a temporary directory. The vulnerability affects PAN-OS on PA-Series and VM-Series firewalls and Panorama (virtual and M-Series). Cloud NGFW and Prisma Access as cloud services are not impacted, though Prisma Access appliances require patching. The risk is minimized by restricting management interface access to only trusted internal IP addresses.

What this means
What could happen
An attacker with network access to the management web interface could delete files from the firewall's temporary directory, potentially disrupting logs or operational data but not directly affecting traffic filtering or device operation.
Who's at risk
Palo Alto Networks firewall administrators managing PA-Series, VM-Series, and Panorama appliances. Organizations running PAN-OS below version 12.1.8 or Prisma Access below 11.2.13 are at risk if their management interfaces are accessible from untrusted networks.
How it could be exploited
An unauthenticated attacker on the network sends requests to the management web interface on the firewall or Panorama appliance and deletes files from a temporary directory via the vulnerability.
Prerequisites
  • Network access to the management web interface (typically port 443)
  • Management interface exposed beyond trusted internal IP addresses
remotely exploitableno authentication requiredmanagement interface exposure
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
PAN-OSBelow 12.1.812.1.8+
Prisma AccessBelow 11.2.1311.2.13+
Remediation & Mitigation
0/4
Do now
0/2
HARDENINGRestrict management web interface access to only trusted internal IP addresses using firewall rules or network segmentation
HARDENINGReview and document which internal IP addresses require management access, then block all other sources at the network perimeter
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

PAN-OS
HOTFIXUpdate PAN-OS to version 12.1.8 or later on PA-Series and VM-Series firewalls and Panorama appliances
Prisma Access
HOTFIXUpdate Prisma Access to version 11.2.13 or later
API: /api/v1/advisories/cc597b91-9fad-482d-9d82-d5a005bf9726

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

PAN-OS: File Deletion Vulnerability in Management Web Interface | CVSS 6.9 - OTPulse