OS Command Injection in Palo Alto PAN-OS - CVE-2026-0286

 

OS Command Injection in Palo Alto PAN-OS - CVE-2026-0286

Published: July 10, 2026


Vulnerability identifier: #VU137303
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0286
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary OS commands as root.

The vulnerability exists due to improper neutralization of special elements used in an OS command in the management plane CLI when processing crafted CLI input. A remote privileged user can send crafted CLI commands to execute arbitrary OS commands as root.

This issue affects the management plane and does not require special configuration to be exposed.


Affected software

Palo Alto PAN-OS

How to mitigate CVE-2026-0286

Install security update from vendor's website.

Palo Alto PAN-OS - addressed in versions 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8, 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16, 11.2.4-h20, 11.2.7-h18, 11.2.10-h11, 11.2.13, 12.1.4-h8, 12.1.7-h2, 12.1.8

External References

Related Security Bulletins