Cross-site scripting in Palo Alto PAN-OS - CVE-2026-0266
Published: June 16, 2026
Palo Alto PAN-OS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary JavaScript in a user's browser session.
The vulnerability exists due to cross-site scripting in the web interface when processing stored administrator-supplied input. A remote privileged user can store a malicious JavaScript payload using the web interface to execute arbitrary JavaScript in a user's browser session.
User interaction is required for the payload to be rendered.