CVE-2026-0279
PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
Description
Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store or execute malicious JavaScript payload. The security risk posed by this issue is minimized when the management interface and access to the User-ID™ Authentication Portal is restricted to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW is not affected by this vulnerability.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cloud NGFW | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | PAN-OS | Firewall / NGFW | cna-assigner |
| Palo Alto Networks | Prisma Access | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (3)
- Palo Alto Networks · Cloud NGFW
- Palo Alto Networks · PAN-OS
- Palo Alto Networks · Prisma Access
Credit
our internal security research teams
Vendor remediation
Version Minor Version Suggested Solution Cloud NGFW No action needed.PAN-OS 12.112.1.2 through 12.1.7-h*Upgrade to 12.1.8 or later.PAN-OS 11.211.2.0 through 11.2.12Upgrade to 11.2.13 or later.PAN-OS 11.111.1.0 through 11.1.15-h* Upgrade to 11.1.16 or later.PAN-OS 10.210.2.0 through 10.2*Upgrade to 11.1.16, 11.2.13, 12.1.8 or later.All older unsupported PAN-OS versions Upgrade to a supported fixed version. Prisma Access 12.112.1.2 through 12.1.7-h* Upgrade to 12.1.8 or later.*Prisma Access 11.211.2.0 through 11.2*Upgrade to 12.1.8 or later.*Prisma Access 10.210.2.0 through 10.2*Upgrade to 12.1.8 or later.* * See the note under Product Status for information regarding Prisma Access upgrades.