OS Command Injection in Palo Alto PAN-OS - CVE-2026-0273
Published: June 16, 2026
Palo Alto PAN-OS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary commands as root.
The vulnerability exists due to command injection in the PAN-OS management interface when handling input through the CLI or Web UI. A remote privileged user can send crafted input to execute arbitrary commands as root.
Exploitation requires access to the PAN-OS CLI or Web UI.