CVE-2026-0308

Summary

A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface.

This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series).

Cloud NGFW and Prisma® Access are not affected by this vulnerability.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksCloud NGFWAllunaffected
Palo Alto NetworksPAN-OS12.2.0 < 12.2.3unaffected
Palo Alto NetworksPAN-OS12.1.0 < 12.1.10affected
Palo Alto NetworksPAN-OS11.2.0 < 11.2.13-h2affected
Palo Alto NetworksPAN-OS11.1.0 < 11.1.16-h2affected
Palo Alto NetworksPrisma AccessAll < 12.1.4-h10unaffected

Weaknesses

  • CWE-79: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Workarounds

No known workarounds exist for this issue.

Customers with a Threat Prevention subscription are provided with limited coverage against this vulnerability by enabling Threat ID 510040 and 510041 (from Applications and Threats content version 9145-10233 and later). For these Threat IDs to protect against attacks for this vulnerability:

Please note that this Threat ID requires SSL Decryption.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References