PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration
Plan PatchCVSS 7.1CVE-2026-0309Sep 9, 2026
Palo Alto Networks
IT in OT - Palo Alto firewalls are commonly deployed at IT/OT network boundaries
Summary
A command injection vulnerability in PAN-OS enables an authenticated administrator to run arbitrary commands as root when the device is configured with a Luna Hardware Security Module (HSM). Exploitation requires valid CLI credentials and Luna HSM configuration. Panorama and Cloud NGFW are not affected. The risk is reduced when CLI access is restricted to a small trusted group.
What this means
What could happen
An authenticated administrator with CLI access to a PAN-OS device configured with a Luna HSM could run arbitrary commands as root, potentially compromising the firewall's integrity and allowing bypass of security controls that protect your network.
Who's at risk
Organizations running Palo Alto Networks PAN-OS firewalls or Prisma Access gateways with Luna HSM integration should prioritize this. Affected users include network administrators managing firewalls and those responsible for HSM-backed encryption or key management in their security infrastructure.
How it could be exploited
An attacker with valid PAN-OS CLI credentials (administrator account) connects to the device management interface and issues a specially crafted command through the CLI that exploits improper input validation in the Luna HSM configuration. This allows the attacker to inject and execute arbitrary system commands with root privileges.
Prerequisites
- Valid PAN-OS administrator CLI credentials
- Network access to PAN-OS management interface
- Device must be configured with Luna Hardware Security Module (HSM)
Requires valid administrator credentialsRequires specific Luna HSM configurationNo authentication bypass needed (insider threat)Allows root-level command execution
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Prisma AccessBelow 12.1.1012.1.10+
PAN-OSBelow 12.2.312.2.3+
Prisma AccessBelow 12.1.4-h1012.1.4-h10+
Prisma AccessBelow 12.1.7-h512.1.7-h5+
Remediation & Mitigation
0/5
Do now
0/1HARDENINGRestrict CLI access to a limited group of trusted administrators and enforce strong authentication
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
PAN-OS
HOTFIXUpdate PAN-OS to version 12.2.3 or later
Prisma Access
HOTFIXUpdate Prisma Access to version 12.1.10 or later
HOTFIXUpdate Prisma Access to version 12.1.4-h10 or later if running 12.1.4 branch
HOTFIXUpdate Prisma Access to version 12.1.7-h5 or later if running 12.1.7 branch
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e5a55645-4dcb-4861-9999-4837a07efe59Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.