OS Command Injection in Palo Alto PAN-OS - CVE-2026-0261
Published: May 19, 2026
Palo Alto PAN-OS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary commands as root.
The vulnerability exists due to command injection in the PAN-OS CLI or Web UI when processing administrator-supplied input. A remote privileged user can send crafted input to execute arbitrary commands as root.
Exploitation requires access to the PAN-OS CLI or Web UI.