Cross-site scripting in Palo Alto PAN-OS - CVE-2026-0256
Published: May 19, 2026
Palo Alto PAN-OS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the web interface when processing stored administrator-supplied input. A remote privileged user can store a malicious JavaScript payload to execute arbitrary script in a victim's browser.
User interaction is required for the crafted content to be viewed.