CVE-2026-0309

Summary

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM).

The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.

Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Affected Software

VendorProductVersion RangeStatus
Palo Alto NetworksCloud NGFWAllunaffected
Palo Alto NetworksPAN-OS12.2.0 < 12.2.3affected
Palo Alto NetworksPAN-OS12.1.0 < 12.1.4-h10affected
Palo Alto NetworksPAN-OS11.2.0 < 11.2.4-h21affected
Palo Alto NetworksPAN-OS11.1.0 < 11.1.4-h36affected
Palo Alto NetworksPAN-OS10.2.0 < 10.2.7-h37affected
Palo Alto NetworksPrisma AccessAll < 12.1.4-h10unaffected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Workarounds

No known workarounds exist for this issue.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References