Vulnerability identifier: #VU137303
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0286
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary OS commands as root.
The vulnerability exists due to improper neutralization of special elements used in an OS command in the management plane CLI when processing crafted CLI input. A remote privileged user can send crafted CLI commands to execute arbitrary OS commands as root.
This issue affects the management plane and does not require special configuration to be exposed.
Affected software
Palo Alto PAN-OS
How to mitigate CVE-2026-0286
Install security update from vendor's website.
Palo Alto PAN-OS - addressed in versions 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8, 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16, 11.2.4-h20, 11.2.7-h18, 11.2.10-h11, 11.2.13, 12.1.4-h8, 12.1.7-h2, 12.1.8
External References
Related Security Bulletins