Improper Neutralization of Special Elements in Output Used by a Downstream Component in Palo Alto PAN-OS - CVE-2026-0284

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Palo Alto PAN-OS - CVE-2026-0284

Published: July 10, 2026


Vulnerability identifier: #VU137305
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-0284
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information or corrupt internal LSVPN satellite data.

The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in the Large Scale VPN (LSVPN) functionality when processing network-supplied XML content. A remote attacker can inject malicious XML content to disclose sensitive information or corrupt internal LSVPN satellite data.

Only firewalls using Large Scale VPN (LSVPN) with configured satellites are vulnerable. Panorama, Cloud NGFW, and Prisma Access are not impacted.


Affected software

Palo Alto PAN-OS

How to mitigate CVE-2026-0284

Install security update from vendor's website.

Palo Alto PAN-OS - addressed in versions 10.2.7-h36, 10.2.10-h39, 10.2.13-h23, 10.2.16-h9, 10.2.18-h8, 11.1.4-h35, 11.1.6-h35, 11.1.7-h8, 11.1.10-h30, 11.1.13-h9, 11.1.16, 11.2.4-h20, 11.2.7-h18, 11.2.10-h12, 11.2.13, 12.1.4-h8, 12.1.7-h2, 12.1.8

External References

Related Security Bulletins