PAN-OS: Authenticated Command Injection in CLI
Plan PatchCVSS 8.5CVE-2026-0286Jul 8, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
A command injection vulnerability in PAN-OS management plane allows an authenticated administrator to execute arbitrary OS commands as root on PA-Series and VM-Series firewalls and Panorama systems. The vulnerability does not affect Cloud NGFW. Risk is reduced if CLI access is restricted to a limited group of administrators.
What this means
What could happen
An authenticated administrator could execute arbitrary commands on the firewall with root privileges, potentially altering security policies, disabling protections, or disrupting network traffic that depends on the firewall.
Who's at risk
Palo Alto Networks firewall and Panorama administrators who manage PA-Series or VM-Series firewalls on-premises. This affects any organization using these devices for network security and policy enforcement. Prisma Access cloud gateway administrators are also affected. Cloud NGFW is not impacted.
How it could be exploited
An attacker with valid administrator credentials gains access to the CLI management interface and injects malicious commands through a vulnerable parameter. The firewall executes these commands with root-level privileges, allowing complete system compromise.
Prerequisites
- Valid administrator credentials
- Network access to the management interface (typically restricted network or VPN)
- CLI access enabled or available
Requires valid administrator credentialsLow exploitation complexityAffects security policy managementRemote network access possible
Exploitability
Some exploitation risk — EPSS score 1.7%
Affected products (7)
7 with fix
ProductAffected VersionsFix Status
PAN-OSBelow 12.1.4-h812.1.4-h8+
PAN-OSBelow 12.1.7-h212.1.7-h2+
PAN-OSBelow 12.1.812.1.8+
Prisma AccessBelow 11.2.4-h2011.2.4-h20+
Prisma AccessBelow 11.2.7-h1811.2.7-h18+
Prisma AccessBelow 11.2.10-h1111.2.10-h11+
Prisma AccessBelow 11.2.1311.2.13+
Remediation & Mitigation
0/5
Do now
0/1WORKAROUNDRestrict CLI administrative access to a limited group of trusted administrators using IP allowlists or VPN-only access
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
PAN-OS
HOTFIXUpdate PAN-OS to 12.1.4-h8 or later (if running 12.1.x below h8), 12.1.7-h2 or later (if running 12.1.x below h7), or 12.1.8 or later (if running 12.1.x below 12.1.8)
Prisma Access
HOTFIXUpdate Prisma Access to 11.2.4-h20 or later (if running 11.2.4 below h20), 11.2.7-h18 or later (if running 11.2.7 below h18), or 11.2.13 or later (if running 11.2.x below 11.2.13)
All products
HARDENINGRoute management traffic through a data plane port with management profile enabled instead of the dedicated management port to enable threat inspection
Long-term hardening
0/1HARDENINGEnable threat prevention (Threat ID 510036) on inbound management traffic if you have a Threat Prevention subscription and can decrypt management interface traffic
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/77900bba-ed3f-4095-ae0b-d3ce53786138Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.