PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
MonitorCVSS 4.8CVE-2026-0308Sep 9, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
A stored cross-site scripting (XSS) vulnerability in PAN-OS software on PA-Series and VM-Series firewalls and Panorama systems allows a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. Cloud NGFW and Prisma Access are not affected.
What this means
What could happen
An authenticated administrator with malicious intent could inject JavaScript code into the firewall's web interface that executes when other administrators access the interface, potentially allowing credential theft or unauthorized configuration changes to critical security policies.
Who's at risk
Administrators responsible for Palo Alto Networks PA-Series firewalls, VM-Series firewalls deployed on hypervisors or cloud platforms, and Panorama centralized management systems should prioritize updating to address this vulnerability. Cloud NGFW and Prisma Access customers are not affected.
How it could be exploited
An attacker with valid administrator credentials accesses the PAN-OS web interface and injects a JavaScript payload into a stored field. When another administrator logs in and views that field, the malicious script executes in their browser session, running with the same privileges as that administrator.
Prerequisites
- Valid administrator account credentials for PAN-OS web interface
- Network access to the management IP address of PA-Series, VM-Series firewall, or Panorama on ports used for web interface (typically 443)
Requires valid administrative credentialsLow complexity attackAffects centralized management systems (Panorama)Insider threat vector
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
Prisma AccessBelow 12.1.1012.1.10+
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict management interface access to trusted administrator networks using firewall rules or network segmentation
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Prisma Access to version 12.1.10 or later
Long-term hardening
0/2HARDENINGImplement multi-factor authentication (MFA) for all administrator accounts accessing PAN-OS management interfaces
HARDENINGEnable logging and monitoring of administrator actions and web interface access for anomaly detection
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b1501634-58fc-4f15-8426-3d9efff8cc1fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.